# Sovereign AI on infrastructure you control

URL: https://www.getdynamiq.ai/use-cases/sovereign-ai

> Run the agent platform, open models and every trace inside your own cloud account or data center, operated by your team, with an open-source SDK.

Run the whole agent platform, the models and every trace inside your own cloud account or data center, operated by your team.

[Start free](https://app.getdynamiq.ai/signup) · [Talk to the team](https://www.getdynamiq.ai/book-a-demo)

_Illustration of a sovereign deployment: the agent platform in the customer's data center, open models served on vLLM on its own GPUs, knowledge indexed from its own document stores, and every trace kept in its own deployment._

In short

A sovereign AI deployment keeps agents, models, data and the record of every decision under your control, on infrastructure you choose and operate. Dynamiq runs the full platform (agents, knowledge, guardrails, evals and traces) inside your own cloud account or data center, serves open models such as Llama, Gemma, Mistral and Qwen inside your environment, so agents can answer without calling an outside model provider. The SDK is open source under Apache-2.0, so the agents you build stay yours.

## The problem

Ministries, central banks, defense organizations and regulated firms are being asked to show that their AI meets the bar of any other critical system: data stays in a known jurisdiction, models run where the organization can inspect them, and a record of every decision is kept on infrastructure it controls. Shared AI services make that hard to prove. Prompts and documents travel to a provider's endpoint, traces sit in a vendor's tenant, and agent logic is locked into a proprietary builder that cannot move. Teams end up choosing between useful agents and control over them.

## What it moves

Calls to outside providers

Which model and tool calls, if any, leave your environment, visible in every run's trace.

Time to a first production agent

How long it takes to go from an empty cluster to an agent your team runs in production.

Audit response time

How quickly you can show an auditor or regulator exactly what an agent did on a given run.

Portability

Whether an agent can move between clusters, clouds or data centers without a rebuild.

## How the agent works

Every step is traced. The steps marked for review wait for a person.

1.  Step 1
    
    A signed-in request
    
    A person signs in through your identity provider with SSO on Enterprise, or a customer channel or scheduled job starts a run, against an agent deployed in your own cloud account or data center.
    
2.  Step 2
    
    Screened before the model
    
    PII and prompt injection detectors screen the input, and a flagged request routes to a refusal or to a person instead of the model.
    
3.  Step 3
    
    A self-hosted model answers
    
    The agent calls an open model served on vLLM inside your environment, so the prompt and the answer stay on your infrastructure.
    
4.  Step 4
    
    Tools reach only your systems
    
    The agent queries your databases, document stores and internal APIs through connections you configure, under each person's own credentials where access must follow their permissions.
    
5.  Step 5
    
    Approval before anything leaves
    
    A payment, a filing or a message to a citizen or customer pauses for a person to approve the exact output, with fields they are allowed to edit.
    
    Human review
    
6.  Step 6
    
    The record stays with you
    
    The run is traced inside your deployment, replayable node by node for auditors, and kept according to the retention controls you set.
    

## Controls

Install from the official Helm chart into your own AWS, Azure, GCP, IBM Cloud, OpenShift or any Kubernetes 1.32+ cluster, or on-premises. Dynamiq holds SOC 2, and signs a BAA for HIPAA workloads and a DPA under GDPR. Our forward-deployed engineers work inside your environment to ship the first production agent with your team and hand it over. Fully isolated or air-gapped environments are delivered with our engineers.

The whole platform in your perimeter

Agents, knowledge bases, guardrails, evals and traces run in your own AWS, Azure, GCP, IBM Cloud, OpenShift or Kubernetes 1.32+ cluster, or on-premises.

Models you host

Open models such as Llama, Gemma, Mistral and Qwen run on vLLM inside your environment, with LoRA adapters fine-tuned on your data, so agents need no outside model provider.

Your identity and your policies

SSO through your identity provider on Enterprise, organization roles and retention controls follow your own policies.

Evidence stays with you

Every run is traced and replayable inside your deployment, exportable for your auditors without a vendor in the loop.

No lock-in

The SDK is open source under Apache-2.0 and runs on the same engine as the platform, and workflows export as YAML, so the agents you build can move with you.

Isolated when required

Fully isolated or air-gapped environments are delivered with our engineers, for networks that cannot reach the public internet.

## Systems it connects to

-   Cloud accounts you own on AWS, Azure, GCP and IBM Cloud
-   Red Hat OpenShift and any Kubernetes 1.32+ cluster, on-premises
-   Open models on vLLM, with LoRA adapters
-   Identity providers over OIDC (Okta, Microsoft Entra ID)
-   Internal databases and warehouses, over SQL
-   Document repositories you host, such as SharePoint
-   Internal APIs and MCP servers
-   Your own carrier over SIP for inbound voice

## Built with

-   [Models and AI Gateway · Use 29 model providers from the SDK, call the most-used models behind one endpoint and one credential, or host and fine-tune open models yourself.](https://www.getdynamiq.ai/product/models)
-   [Apps and deployments · Deploy a saved workflow version as an App with its own hostname. Call it over HTTP, embed a chat widget, or trigger it on a schedule or an event.](https://www.getdynamiq.ai/product/deployments)
-   [Guardrails and approvals · Detect PII and prompt injection before a model sees them, enforce content policies, and pause tool steps for a person to approve.](https://www.getdynamiq.ai/product/guardrails)
-   [Observability · Every run is traced and replayable, node by node, with the cost, latency and tokens each step used.](https://www.getdynamiq.ai/product/observability)

## Industries

-   [Government and public sector · Citizen services, benefits and permit review, and program reporting, with a person in the loop and your agency in control of the infrastructure.](https://www.getdynamiq.ai/industries/public-sector)
-   [Financial services · Back-office automation, customer service by phone and chat, and KYC and AML work, on one governed platform your compliance team can audit.](https://www.getdynamiq.ai/industries/financial-services)
-   [Insurance · Answer policyholders by phone and chat, prepare claims and underwriting files, and keep an adjuster or underwriter approving every decision.](https://www.getdynamiq.ai/industries/insurance)
-   [Telecommunications · Answer subscriber calls and chats in their own language, reconcile billing, and give support and network teams answers with a citation attached.](https://www.getdynamiq.ai/industries/telecommunications)
-   [Healthcare · Patient intake, referral and document review, and clinical knowledge assistants, with PII and prompt injection screened before a model reads anything.](https://www.getdynamiq.ai/industries/healthcare)

## Questions and answers

### What is sovereign AI?

It is control over the whole AI stack: the infrastructure it runs on, the models it uses, where data and logs are stored, and who operates it. For agents, that means the platform, the models and every trace stay on infrastructure your organization controls, with no dependency you cannot replace.

### Can Dynamiq run with no calls to outside model providers?

Yes. Serve open models on vLLM inside your environment and point your agents at them, so prompts and documents stay on your infrastructure.

### Which models can we run ourselves?

Open-weight models such as Llama, Gemma, Mistral and Qwen, served on vLLM, with LoRA adapters fine-tuned on your own data. Hosted providers stay optional.

### Can it run fully air-gapped?

Yes. Fully isolated or air-gapped environments are delivered with our engineers, on top of the standard self-hosted install.

### Are we locked in to Dynamiq?

No. The SDK is open source under Apache-2.0 and runs on the same engine as the platform, and workflows export as YAML, so what you build stays yours.

### Do your engineers work inside our environment?

Yes. Forward-deployed engineers work inside your environment with your team: they run a bootcamp, ship the first production agent with you, then hand it over.

### Can we buy through our cloud marketplace?

Yes. Available on AWS Marketplace, Microsoft Azure Marketplace and IBM Marketplace, so it can be procured through a cloud account you already have.

## See this agent on your data.

Talk to our team. We will walk through how it works in your environment, with your systems.

[Start free](https://app.getdynamiq.ai/signup) · [Talk to the team](https://www.getdynamiq.ai/book-a-demo)
