Private AI

Your data doesn't go to Third-party LLMs.

Knowi's own AI answers the questions, runs the search, and reads the documents. All of it inside Knowi. Want OpenAI or Claude instead? Turn them on for the features you pick. They are off until you do.

Managed cloud, on-premises, hybrid, or air-gapped. SOC 2 Type II attested controls.

settings / ai / model routing in boundary
Where each AI function runs
Natural language query Knowi AI in boundary
Vector search Knowi AI in boundary
Document AI Knowi AI in boundary
Third-party model optional off
boundary: Knowi infrastructure | egress to external LLM: none
Definition

What Private AI means here

Private AI means the AI reading your data runs somewhere you control, not on a model vendor's API. In Knowi that boundary is the Knowi platform: the models, the inference, and the vector search are all part of it, not a wrapper around someone else's LLM.

This is what security reviews actually ask about. Not "is it encrypted". More like: where does the prompt go, what gets sent with it, and who else can read the answer. When the model lives outside your vendor's boundary, the honest answer to all three is: it depends on their sub-processor.

1Models

Knowi AI is the default

Inference runs on Knowi infrastructure. Nothing goes to an outside model unless you switch one on.

Egress to third-party LLM: none by default
2Choice

Third-party models are optional

Turn on OpenAI or Claude for one feature, keep the rest on Knowi AI, and switch back whenever you want.

Scope: per feature, reversible
3Deployment

Run it where the data lives

Managed cloud, on-premises, hybrid, or air-gapped. On-premises runs the full platform, all agents, and your own LLM.

Delivery: Docker or Kubernetes
4Documents

Unstructured data too

Query PDFs, Word files, and other unstructured documents through the same private path as your databases.

Feature: Document AI

Everyone encrypts your data.
Fewer can tell you whose model reads it.

How it works

Model, Deployment, Governance

Most AI analytics tools pick the model, the location, and the data path for you. Knowi makes them three separate choices.

Model

Own AI, not a wrapper around someone else's LLM

Models, inference, and vector search all stay inside Knowi. So when someone asks whether an outside model sees your data, the answer is just no.

  • Knowi AI powers natural language query, Document AI, and vector search
  • OpenAI and Claude available per feature, off unless you turn them on
  • No vendor lock-in: switch model providers without rebuilding your analytics
Model routing
defaultKnowi AIin boundary
optionalOpenAIoff
optionalClaudeoff
on-premYour own LLMsupported
Deployment

Run it On-premises

If you are regulated, where it runs is the whole answer. On-premises and air-gapped installs put the entire platform inside your infrastructure, agents included.

  • Managed cloud, on-premises, hybrid, or air-gapped
  • On-premises customers run the full platform, all agents, and their own LLM via Docker or Kubernetes
  • Meets strict data residency requirements without a separate architecture
Read the security detail
Deployment options
cloudKnowi managedavailable
on-premYour infrastructureavailable
hybridSplit control planeavailable
air-gappedNo outbound networkavailable
Governance

The paperwork your security team wants

Knowi's IT controls are audited by independent firms and verified in a SOC 2 Type II report, prepared under AICPA attestation standards and ISAE international standards. Ask and we will send it.

  • SOC 2 Type II attested controls, report available on request
  • HIPAA-aligned controls, with a BAA available for healthcare deployments
  • Encryption in transit and at rest, SSO, and role and row-level access controls
Healthcare deployments
Compliance posture
soc 2Type II, independently auditedattested
hipaaAligned controls, BAA availablesupported
accessSSO, role and row-levelenforced
residencyRegion or on-premyour choice
Compare

Private AI vs a tool that calls a public model

On a pricing page they look the same. The difference is where your data goes.

Question
Analytics tool on a third-party LLM API
Knowi Private AI
Who runs the model
An external model provider, usually named as a sub-processor
Knowi, inside the Knowi boundary, or your own LLM when self-hosted
What leaves your boundary
Prompt plus whatever schema, rows, or results are needed for context
Nothing goes to a third-party model by default. On-premises, nothing leaves your environment at all.
Can you turn the external model off
Rarely. The AI features usually stop working without it.
It is off unless you enable it, per feature, and reversible
Air-gapped deployment
Not possible while the AI depends on an outbound API call
Supported, with the full platform and all agents running locally
Unstructured documents
Uploaded to the model provider to be embedded and queried
PDFs, Word files, and other documents queried through the same private path
Who needs this

For regulated industries and beyond

01

Healthcare and PHI

Analytics on protected health information, where one third-party model call turns into a disclosure question. HIPAA-aligned controls, a BAA on request, and on-premises for teams that will not send PHI anywhere.

02

Financial services

Residency and audit requirements that outlive any model vendor's terms of service. Plus being able to prove which model saw what.

03

SaaS with embedded analytics

You inherit your vendor's AI sub-processors, and you have to disclose them to your own customers. Keeping inference inside Knowi keeps that list short.

FAQ

Frequently asked questions

What is Private AI in analytics?

Private AI means the AI powering your analytics runs inside a boundary you control rather than calling an external model vendor's API. In Knowi, the models, inference, and vector search are part of the platform itself, so the default path for a natural language question never reaches a third-party LLM.

Does Knowi send my data to OpenAI or Claude?

Not by default. Knowi AI is the default and runs inside the Knowi boundary. OpenAI and Claude can be enabled per feature if you want to use them, and turned off again at any time, so third-party models are an option rather than a dependency.

Can I run Knowi's AI entirely on my own infrastructure?

Yes. On-premises customers run the full platform, all agents, and their own LLM via Docker or Kubernetes. In that deployment, data does not leave your environment at all, which is also what makes an air-gapped install possible.

Is Private AI available on Knowi's managed cloud?

Yes, with a narrower boundary. On managed cloud, models, inference, and vector search stay inside the Knowi boundary and are not sent to a third-party model provider. If your requirement is that data never leaves your own infrastructure, that calls for the on-premises or air-gapped deployment.

What compliance evidence can Knowi provide?

Knowi maintains IT controls audited by independent firms, verified in a SOC 2 Type II report prepared in accordance with AICPA attestation standards and ISAE international standards. The report is available on request. For healthcare deployments, Knowi operates HIPAA-aligned controls and can sign a BAA.

Can Private AI query unstructured documents?

Yes. Document AI lets you query PDFs, Word files, and other unstructured documents through the same private path as your databases, so the contents are not uploaded to an external model provider to be embedded.

Does using Private AI limit which data sources I can analyze?

No. The AI boundary is independent of connectivity. Knowi connects natively to relational databases, NoSQL stores, and REST APIs and joins across them without moving the data into a warehouse first, whichever model configuration you choose.

See how private AI will run for your usecase.

We will walk the data path end to end. Which model runs where, what leaves, and what an on-premises install looks like.

SOC 2 Type II attested controls. Report available on request.