Architecture

You choose where it runs. What that choice decides about your data, and about what it costs to operate.

Architecture

One workspace. You choose where it runs and which models it uses.

You choose where it runs. I build it and hand it over to your team. I agree the configuration and operating responsibilities with you before building. Hardware ownership, data routes and access need checking for each setup.

Workspace and model choices

Different models in the same workspace

One workspace can connect to different models: OpenAI, Anthropic, or open models on servers you control. It can sit in your cloud account or on your own hardware. I agree with you which requests may reach each provider before building. Changing the model need not mean rebuilding the workspace or how your team uses it.

What I scope with you

I agree the workspace, document handling and model connections with you. External providers use your own API keys. I scope access controls, encrypted connections, backup and restore checks for the chosen environment. I document the configuration and walk your team through it before handover.

When the architecture is a decision

Air-gapped environments, unusual residency obligations, retrieval across a large corpus, or assessment workflows like the one on the previous page. These can change what needs building. I assess them with you before agreeing the architecture.

The architecture follows your requirements. I check the information the workspace may use, the models it needs and who will operate it. I do not assume one hosting arrangement is right for every build.

Your own hardware

You own the machines. Open models can run locally. Data routes, connected services, capacity and total cost still need checking.

Machines
Yours
Built by
CPLT
Run by
You

Private cloud

Your own cloud account. Tenancy, enabled services, model endpoints and provider terms determine the data routes and costs.

Machines
Rented, your account
Built by
CPLT
Run by
You

Shared cloud

Shared infrastructure may be an option. I assess the provider's access controls, data handling and costs against your requirements.

Machines
Shared
Built by
CPLT
Run by
You

You supply the external provider accounts and API keys. Provider usage charges are separate from the build. I document which services receive requests and check the configured routes with you. Local open models are another option.

Your team operates the result. I document configuration and operating procedures, then test the handover with your team. Support has its own agreed scope. I do not offer a managed-service tier.

On premise, the hardware decides what you can run. In the cloud, the GPU decides what you pay. Those are two different problems. A model must fit the available memory and handle the expected workload. Cloud resources also have capacity limits and usage charges. A dedicated GPU can cost more than the licences it replaces. I compare the full cost for your workload rather than assume cloud or local hosting is cheaper.

Document retrieval can add indexing, storage and update costs. The method depends on the documents and the questions your team needs to answer. I include these costs in the assessment before agreeing a build.

What actually determines your data boundary+

I check the actual data routes for the chosen setup. Hosting location alone does not establish the boundary. These four choices need reviewing.

The choiceWhat it decides
Whose tenancy inference runs in The account, tenancy, service configuration and provider terms all matter. I check where requests are processed rather than infer it from the account name.
Whether you use retrieval Indexing and storage can introduce additional data routes. I check the selected retrieval method, including any external embedding service.
Which model endpoints you enable Open models can run on hardware you control. An external model endpoint receives the data sent to it. I agree enabled routes with you and test them.
Who holds the encryption keys Key ownership and management depend on the services selected. I verify what they support and document who can access or recover the keys.

I document the agreed boundary. I record the selected services, permitted data routes and checks in the written scope. A change of model or service needs a fresh check of those routes.

This is a demonstration, not a customer result. My services and contact route are on cplt.tech. Start with a free 45-minute scoping call and a one-page written note. Any paid work has a written scope and price agreed first.

Request a free call ↗ Back to cplt.tech ↗