Cloud • On-Premises • Air-Gapped

Define exactly where your data and AI layer run.

Evaluate Cayra in a managed Cloud VM dedicated to your organization, on your own servers, or with Cayra Nova in a suitable air-gapped environment. Document data flows, access boundaries, and operating responsibilities before deployment.

Customer-dedicated Cloud VM, On-Premises, and Air-GappedOffline inference with Cayra NovaLeast-privilege access and verifiable data flows

Your architecture defines your security boundary.

Where data, the application, and the language model run is documented according to the Cloud, On-Premises, or Air-Gapped architecture you select.

02 — Three deployment models

Choose an architecture that matches your control requirements.

Position Cayra around your security, operating, and infrastructure needs—from a customer-dedicated Cloud VM to the network isolation of an air-gapped environment.

Cloud01 / 03

Start quickly with managed Cloud

Every Cloud customer receives a dedicated virtual machine (VM) managed by Cayra; the proposal also documents the data region, LLM provider, retention period, and access boundaries.

  • Isolate the application workload and tenant runtime from other customers at the customer-dedicated VM boundary
  • Specify the data region and subprocessors in writing
  • Confirm retention, deletion, and model-training-use terms
  • Assign network, identity, and operating responsibilities

A customer-dedicated VM does not automatically mean a dedicated physical host, private cloud, certification, or zero retention. Confirm the selected offer, data flow, and architecture separately.

On-Premises02 / 03

Run Cayra in your own infrastructure

Deploy the application on your servers or in your private cloud while applying your network, identity, data-retention, and operating policies.

  • Confirm server, network, and dependency requirements
  • Record where the LLM component runs and which data it processes
  • Assign update, backup, and incident-response responsibilities
  • Review support access and log-retention terms with your security team

Suitability for deployment in your environment or private network is determined after the technical review.

Air-Gapped • Cayra Nova03 / 03

Work offline with Cayra Nova

In closed networks with sufficient compute infrastructure, Cayra runs with our proprietary language model, Cayra Nova, processing reporting questions without sending them to external LLM services.

  • Place the Cayra and Cayra Nova components in a closed network segment
  • Validate GPU or CPU, memory, and storage capacity against the expected workload
  • Define a controlled transfer process for model packages and software updates
  • Align logs, backups, monitoring, and support with your security policy

Air-gapped deployment is offered after the technical review confirms suitable infrastructure, supported product and Cayra Nova versions, and an offline update procedure.

Four records to document for every model

Defined in writing during the technical review before the pilot.

01Source system, version, and connection path
02Processed data, LLM flow, and Cayra Nova execution location
03Identity, database account, and permission scope
04Operations, offline updates, support, and incident-response ownership
03 — Data and model boundary

Know where data goes and where the model runs.

For Cloud deployments, document the provider and data flow. For air-gapped deployments with suitable infrastructure, questions, schema context, and query results are processed by Cayra Nova within your organizational network.

Do not assume a data flow; verify it through an architecture diagram, contract terms, and technical testing.

01

Identify which user questions, schema context, and query results reach the LLM

02

Record the LLM provider, data region, and subprocessors

03

Document retention or zero-retention periods and restrictions on model-training use

04

Verify masking, deletion, question-history, and query-history rules

05

For air-gapped deployments, use network testing to confirm the Cayra and Cayra Nova components stay within the organizational boundary

Technical and security approval should be based on the selected deployment's written data flow and test record, not a sales presentation.

04 — Pilot access boundaries

Start the security review with least-privilege data access.

Open the pilot account only to the data objects and reporting questions it needs. Do not assume existing ERP roles carry over automatically; test visibility and user scope separately.

01

Create a separate database account and required-object list for the pilot

02

Restrict the account to SELECT, then test that write and DDL operations are blocked

03

Verify the company, table, column, and row scope visible to each user

04

Document access, retention, and deletion terms for question and query history

Read-only access is a pilot acceptance criterion to test, not a slogan.

Use financial, regulatory, or business-critical outputs only after checking scope and filters and receiving approval from the authorized report owner.

05 — Procurement and security review

Four questions to answer before the pilot starts

Answer these questions for the proposed deployment and customer environment, rather than for the product in general.

01

Which data reaches which system and model?

Map user questions, schema context, SQL text, query results, and history separately. Show the Cloud provider or, for an air-gapped scenario, Cayra Nova's execution boundary on that flow.

02

How narrowly can database access be scoped?

List the required tables and views, use a separate SELECT account, block write and DDL operations, and test company and user scope with real pilot questions.

03

Who owns deployment and operations?

Clearly divide infrastructure, model-compute capacity, offline updates, backups, monitoring, support access, and incident-response tasks between the provider and customer.

04

How does a report reach authorized approval?

Compare the pilot report with an approved reference for the same period, filters, and data scope. Explain differences and treat critical output as validated only after the report owner accepts it.

Architecture fit review

Match the deployment model to your security requirements.

Evaluate Cloud, On-Premises, or Air-Gapped deployment against your data sources, LLM flow, and security policy. If you need Cayra Nova, include infrastructure and offline operating requirements in the technical scope.