Control by architecture, not by marketing claim

Keep approved AI workloads closer - and keep the responsibilities visible.

A private AI server can reduce external data sharing and give an organisation more control over models, access, retention and uptime. It does not automatically make the organisation secure, accurate or UK GDPR compliant.

Decision in one minute

Choose private AI when data route, offline operation, model control or shared sustained capacity has real value. Keep a governed cloud fallback where quality, resilience or specialist capability requires it.

Diagram showing an approved request, a local service, an approved store and a policy-controlled data path
Diagram showing an approved request, a local service, an approved store and a policy-controlled data path
A private deployment starts with the permitted data path, access policy and logging boundary. Original explanatory plate. It sets out a decision method, not a measured result.
A private deployment starts with the permitted data path, access policy and logging boundary.

Buyer field note

Let the work and the room reject the wrong machine.

01 / Fit
Start with the accepted task, not a chassis or GPU headline.
02 / Site
Check power, cooling, noise, network and maintenance access.
03 / Alternative
Keep cloud, colocation or a smaller system in the decision.
Diagram showing approved documents moving through a searchable index to an answer with a source citation
Diagram showing approved documents moving through a searchable index to an answer with a source citation
A retrieval workflow should connect each useful answer to approved source material and defined refusal behaviour. Original explanatory plate. It sets out a decision method, not a measured result.
A retrieval workflow should connect each useful answer to approved source material and defined refusal behaviour. Original explanatory plate. It sets out a decision method, not a measured result.

Private means you control the deployment boundary

Prompts, documents, embeddings, logs and outputs can remain on infrastructure the customer owns. Access can be limited to the customer network, VPN or a designed offline environment.

The organisation still needs a lawful basis, retention policy, user controls, accuracy process, incident response, backup and model governance. We make that shared-responsibility boundary part of the order and handover.

Capacity budget

Memory demand has more than one layer

Model
Weights and quantisation.
Context
Working input and cache.
Concurrency
Simultaneous active work.
Headroom
Operations and change allowance.
The bands are a checklist, not a scale. Exact memory belongs to a named model and test. Decision aid for: Private means you control the deployment boundary

Connect the category to the physical and operating system.

Platform views and technical plates show what must be tested beyond a product label or aggregate specification.

GPU server remote management dashboard with system status, access logs and sensor monitoring panels
GPU server remote management dashboard with system status, access logs and sensor monitoring panels
Supplier screenshot of the platform management interface. The final management features and access policy depend on the ordered system. OEM supplier reference image. Written reuse permission pending.
Supplier screenshot of the platform management interface. The final management features and access policy depend on the ordered system. OEM supplier reference image. Written reuse permission pending.
Diagram of an evidence pack containing an asset schedule, burn-in record, health readings, workload test and admin guide
Diagram of an evidence pack containing an asset schedule, burn-in record, health readings, workload test and admin guide
A credible handover records the supplied assets, checks, operating evidence, instructions and unresolved items. Original explanatory plate. It sets out a decision method, not a measured result.
A credible handover records the supplied assets, checks, operating evidence, instructions and unresolved items. Original explanatory plate. It sets out a decision method, not a measured result.

An open stack without a licence-key trap

The baseline uses reviewed open-source components such as Ollama, vLLM or llama.cpp and a browser interface such as Open WebUI. Versions, model sources and licences are recorded.

Open weights are not always unrestricted, and open software still needs updates. The value is portability and inspectability - not a promise of zero maintenance.

Site boundary

The room is part of the specification

  1. Electrical Circuit, protection and UPS policy.
  2. Thermal Airflow, room heat and cooling route.
  3. Network Access, bandwidth and isolation.
  4. Service Rack space, noise and maintenance access.
A technically suitable server is still the wrong purchase when the operating site cannot support it. Decision aid for: An open stack without a licence-key trap

Private-first hybrid is often the sensible answer

The best recommendation may be cloud, local, hybrid - or wait. A fit check should be allowed to say so.

Routine and sensitive work can use the local endpoint. Explicitly approved low-risk or quality-critical work can use a hosted model. A routing policy determines which route is allowed.

This avoids the false choice between sending everything to a provider and pretending one local model can replace every frontier service.

Procurement record

Make the route to acceptance inspectable

  1. Fit brief Workload and alternatives recorded.
  2. Reference test Conditions and results retained.
  3. Exact build Bill of materials and substitutions visible.
  4. Handover Owners, versions and exclusions signed off.
The evidence trail should explain why this platform was chosen and what remains outside the order. Decision aid for: Private-first hybrid is often the sensible answer

Evidence before assurance

Each exact reference configuration needs burn-in, model/runtime smoke tests and performance results with disclosed conditions. Security claims need a defined configuration and owner.

Until those gates are complete, this site publishes the proposed architecture and pricing transparently but does not present untested benchmarks or customer outcomes.

Questions answered

Straight answers to common questions

Is a local AI server automatically UK GDPR compliant?

No. Local hosting can support data minimisation and control, but compliance also depends on lawful basis, transparency, accuracy, security, retention, rights handling and governance.

Does private AI mean no internet connection?

Not necessarily. Private deployments can be connected, restricted, hybrid or designed for offline operation. Updates, model downloads and support routes must be planned for the chosen state.

Will data ever leave the server?

That depends on the agreed architecture, integrations, telemetry and any hosted fallback. We document the data route and disable unapproved external services; the customer owns ongoing configuration.

Primary-source register

Check the live rule or price before relying on it.

Reviewed 26 July 2026. These links support the dated statements on this page; they do not replace legal, tax, security or professional advice.

Put the claim to work

Turn this guidance into a testable requirement.

The brief asks about workload and operating conditions - not just budget.