Private is not the same as secure
Security controls with a named owner on both sides.
Local hosting can reduce external disclosure, but it also moves responsibility onto the organisation. The handover should make control ownership visible rather than imply the box is secure forever.
Buy only when the customer has a technical owner for identity, network, backup, updates and incident response - or contracts those duties separately.
Operational ownership
The handover should make responsibility easier to see.
- 01 / Owner
- Name who controls updates, access, recovery and incidents.
- 02 / Record
- Make versions, tests and handover evidence visible.
- 03 / Exit
- Keep portability and supplier boundaries written down.
The proposed technical baseline
Named administrator access, SSH hardening, host firewall, controlled network exposure, TLS where appropriate, secrets transfer, version records, GPU/system metrics and a defined log-retention setting form the starting point.
The exact controls depend on whether the system is connected, restricted, hybrid or offline.
- Identity and least privilege
- Network segmentation
- Encrypted backups where ordered
- Documented recovery and update state
Change record
A controlled change leaves an evidence trail
- Request Reason, owner and affected service.
- Test Focused acceptance and rollback plan.
- Approve Named person accepts the change.
- Record Version, date and result retained.
Look behind the claim at the operating record.
Management, recovery, evidence and physical serviceability make responsibilities easier to inspect at handover.
Customer responsibilities remain real
The customer owns user lifecycle, acceptable use, data and model approval, physical access, retention, data-subject handling, incident response and daily availability unless a separate agreement changes that.
A RACI is part of a serious deployment, especially where a marketplace mode or cloud fallback is considered.
Recovery boundary
Recovery spans equipment, configuration and business data
- Equipment Hardware fault and warranty route.
- System Build record, settings and secrets.
- Data Backup, retention and restore authority.
- Service Fallback, incident and return to use.
AI adds specific risks
Prompt injection, poisoned documents, over-broad retrieval, unreviewed models and confident inaccurate outputs require controls beyond a conventional file server.
Source citations, permission-aware retrieval, evaluation sets, user training and human review are part of the operating design.
Exit path
Ownership should preserve a practical route out
No certification claim without certification
The proposed appliance is not marketed as automatically UK GDPR compliant, Cyber Essentials certified, NHS DSPT compliant, SRA approved or FCA approved.
Those frameworks and sector obligations can guide the design, but organisational assurance requires its own evidence.
Questions answered
Straight answers to common questions
Is the server secure out of the box?
It can be supplied with an agreed baseline, but security depends on the final network, users, data, updates and operating ownership.
Can it be air-gapped?
An offline or air-gapped design can be scoped, including controlled update and transfer procedures. It is not a default hardware feature.
Do you provide 24/7 monitoring?
Not in the initial supply-and-onboard proposition. Any managed monitoring or response time requires a separate service agreement.
Primary-source register
Check the live rule or price before relying on it.
Reviewed 26 July 2026. These links support the dated statements on this page; they do not replace legal, tax, security or professional advice.
Continue the decision
Useful next steps
Put the claim to work
Turn this guidance into a testable requirement.
The brief asks about workload and operating conditions - not just budget.