Solutions
AI assurance without sending anything outside
Public bodies are being asked to adopt AI and to prove it is governed, often under a sovereignty constraint that rules out most of the market. SAF3AI runs entirely inside your own boundary — air-gapped if required, with local models — and still gives you the full detection, inventory and audit picture.
Capabilities
Key Features
Deploy inside your own boundary
Self-hosted on Kubernetes or bare metal, with a fully air-gapped option. Prompts, documents and telemetry never leave your network, and there is no outbound connectivity requirement.
Local models, no external calls
In sovereign deployments the classification and analysis models run locally. Nothing about your data reaches a commercial model provider, because nothing needs to.
Citizen data protection
Validated detectors for personal and sensitive data, with lineage showing how it moved through an assistant — the evidence a data-protection review actually asks for.
Complete audit trail
Every platform action, every automated response and every access to citizen data recorded and exportable — for the auditor, the ombudsman or the inquiry.
Framework alignment
Control mapping and evidence generation for NIST AI RMF, ISO 42001 and the EU AI Act, so an AI assurance obligation is a report rather than a project.
Shadow AI in a regulated workforce
Discovery of the AI tools staff have adopted on their own, ranked by vendor and data risk — usually the first question a public-sector AI policy has to answer.
Sovereignty
What air-gapped actually means here
The word gets used loosely. In a SAF3AI sovereign deployment it means the platform has no outbound connectivity requirement at all — not that traffic is routed through an approved egress.
No outbound calls
Detection, classification and investigation run against locally hosted models. There is no commercial model provider in the path.
Offline updates
Detection rules and platform updates are applied from signed bundles you transfer in, on your own schedule.
Your infrastructure
Kubernetes or bare metal inside your accredited environment, running on your hardware under your operational control.
Your key management
Encryption keys are managed by your own KMS or HSM rather than a service you do not operate.
Your retention rules
Retention periods and deletion schedules set to your records-management policy, not to a vendor default.
Exportable evidence
Audit trails and compliance evidence export in standard formats, so nothing you need for oversight is locked in.
Sovereign deployment is scoped per engagement — accreditation environments and update processes differ enough that a generic answer would be misleading. Talk to us about your specific constraints and we will tell you plainly what does and does not work.
Get started with Public Sector
See how Saf3AI can help secure your AI agents.