Skip to main content

REFERENCE ARCHITECTURE

One control model across every deployment boundary.

See how governance reaches local enforcement points while model traffic, enterprise data and runtime evidence stay on customer-approved paths.

Four deployment patterns. One governed architecture.

The placement changes with the environment. The policy, identity, approval and audit model stays consistent.

01

Customer cloud

A single-tenant deployment inside a cloud account and region your organisation approves.

Topology

Iftah control planePolicy, identity and audit

Customer cloud account

Private network, compute, storage and keys under customer control

Private computeApproved model workloads
Local enforcement pointPolicy applied near the workload
Customer storage and keysApproved data services

Request and data flow

  • ControlControl planeLocal enforcementGovernance configuration and decisions
  • DataApplicationsPrivate computeRequests use the approved private path
  • DataPrivate computeCustomer dataRetrieval stays on approved services

02

On-premises

Model serving and data services run in infrastructure operated inside your data centre.

Topology

Iftah control planePolicy, identity and audit

Customer data centre

Local compute, network controls and enterprise data services

GPU infrastructurePrivate model serving
Local enforcement pointAccess and action controls
Enterprise dataApproved internal sources

Request and data flow

  • ControlControl planeLocal enforcementPolicy and identity decisions
  • DataApplicationsGPU infrastructureInference follows private network paths
  • DataModel workloadsEnterprise dataAccess remains locally enforced

03

Hybrid

Govern approved cloud and on-premises workloads through one policy and audit model.

Topology

Iftah control planeShared governance across environments

Connected customer environments

Approved private connectivity between cloud and on-premises workloads

Cloud workloadsApproved private cloud services
On-premises workloadsLocal model and data services
Private connectivityCustomer-approved network path

Request and data flow

  • ControlControl planeLocal enforcementOne policy and audit model
  • DataApplicationsApproved workloadsRequests route to the selected environment
  • DataWorkloadsLocal dataData access follows environment policy

04

Air-gapped

A fully disconnected installation with governance, model serving and audit inside the boundary.

Topology

Disconnected customer environment

No external runtime dependency

In-boundary control planeLocal policy, identity and audit
Offline model servingDisconnected inference workloads
Signed artifactsModels and software verified on site
Local audit storeEvidence retained in the environment

Request and data flow

  • ControlLocal control planeModel servingGovernance is enforced inside the boundary
  • DataSigned artifactsModel servingApproved assets are transferred and verified
  • DataModel servingLocal auditRuntime evidence remains in the environment

Match the pattern to your environment.

We can map the boundary, control-plane placement, private network path and review evidence for your first workload.

Review Your Architecture