Full Data Sovereignty: Air-Gapped AI

Secure, Self-Hosted
On-Premises AI Platform

Enterprise-grade AI that runs entirely on your infrastructure. No external API calls. No data leaving your network. Full regulatory compliance built in.

Zero-Trust AI Access Control
Compliance HIPAA / SOC 2 / GDPR
Self-Hosted Your Infrastructure
Air-Gapped No Internet Required

The Security Gap

Before Knox

Direct Connection (High Risk)

Employee
PII / Secrets Exposed
Public AI
Data leaves network
Data Leak
With Knox

Air-Gapped Local AI (Zero Risk)

Everything stays on your infrastructure
Employee
Encrypted
Project Knox
Sanitize + Audit
Sanitized
LOCAL Ollama LLM On Your Server
0%
Data Leaves
100%
On-Premises
Full
Compliance

The Business Challenge

The AI Dilemma: Balancing Risk vs. Productivity

Option A: Fast but Risky

Using public AI directly

  • - Data leaves your perimeter
  • - Unknown retention policies
  • - Regulatory violations (HIPAA/GDPR)
Unmanaged Risk

Option B: Safe but Limiting

Banning AI entirely

  • - Competitive disadvantage
  • - Shadow IT proliferation
  • - Employee frustration
Innovation Stalled

Project Knox

Local AI, Full Control

  • + AI runs on your infrastructure
  • + Zero data leaves your network
  • + Immutable audit trail
  • + Air-gapped deployment ready

What Project Knox Does

Enterprise AI with defense-in-depth security -- running entirely on your infrastructure.

PII/PHI Sanitization

Dual-layer detection using Microsoft Presidio and a local LLM. Catches structured patterns (SSN, credit cards) and context-aware sensitive data across 22 languages before it reaches the AI model.

Access Control

Enterprise-grade SSO (SAML, OIDC) via Keycloak with mandatory MFA. Role-based permissions, per-user rate limiting, and context-aware access policies.

Regulatory Compliance

Automated reporting mapped to HIPAA, SOC 2, GDPR, CCPA, NYDFS 500, and the EU AI Act. Immutable audit trails with 7-year retention and fail-closed logging.

Data Sovereignty

Fully air-gapped deployment. No external API calls, no vendor lock-in, no data residency concerns. Five isolated Docker networks ensure defense-in-depth with AES-256-GCM encryption at rest and TLS 1.3 in transit.

22 Languages + RTL

Full UI localization across 22 languages including Arabic and Hebrew with native RTL layout support. PII/PHI detection works across all supported languages. Deploy once, serve your entire global workforce.

Supported Languages

English Español Français Deutsch Português Polski Română Magyar Türkçe Русский Українська العربية עברית 中文 日本語 한국어 हिन्दी ไทย Bahasa தமிழ் සිංහල Afrikaans

How It Works

A four-layer defense-in-depth security model -- all running on your servers.

1

The Front Door

API Gateway

Controls who can enter and how often. Prevents abuse and enforces access policies via Kong Gateway with Keycloak SSO.

2

The Security Scanner

Content Sanitization

Dual-layer detection: Microsoft Presidio catches structured patterns, a local LLM catches context-dependent sensitive data. If either layer flags it, it gets redacted.

3

Local Intelligence

On-Premises LLM

Sanitized content is processed by Ollama running locally on your infrastructure. No internet connection needed. Data never leaves your network.

4

The Vault

Audit System

Records every interaction with fail-closed logging. Enables compliance reporting and incident investigations with immutable, encrypted audit trails.

Is Knox Right For You?

Best Fit If:

  • You handle sensitive data (PII, PHI, IP)
  • You operate in regulated industries
  • Data cannot leave your network
  • You need verifiable audit trails

Not Necessary If:

  • You are a very small team (<10 people)
  • You handle no sensitive data
  • You have unlimited risk tolerance
  • You don't need audit trails

Frequently Asked Questions

Does it require internet access?

No. Knox is designed for fully air-gapped deployment. All LLM inference runs locally via Ollama on your own servers. There are zero external API calls -- no data ever leaves your network perimeter. Internet is only needed for initial model downloads, after which the system operates completely offline.

What AI models does it run?

Knox runs open-source models locally via Ollama, including Llama 3.1 (8B and 70B parameters), Mistral 7B, and Code Llama 13B. You choose which models to deploy based on your hardware and use case. Models run entirely on your infrastructure with no external dependencies.

Does Knox support international languages?

Yes. The entire UI is fully localized in 22 languages -- including Arabic and Hebrew with native right-to-left (RTL) layout. Users select their preferred language and the full interface (chat, admin, compliance reporting, settings) renders natively. PII/PHI sanitization also works across all supported languages, and the local Llama models handle multilingual conversations natively.

Where is data stored?

All data -- conversations, audit logs, user records, and model weights -- stays on your infrastructure. Nothing is sent to external services. Content is encrypted at rest with AES-256-GCM via HashiCorp Vault, and all network communication uses TLS 1.3.

Can Knox integrate with our existing systems?

Yes. Knox integrates with standard enterprise identity providers (Okta, Azure AD, LDAP) via Keycloak, and logging stacks (Splunk, Datadog, Graylog) for SIEM integration. The RAG pipeline supports local document ingestion with vector search.

Is it HIPAA / GDPR compliant?

Knox provides the technical controls required for HIPAA, SOC 2, GDPR, CCPA, NYDFS 500, and EU AI Act compliance: encryption at rest and in transit, immutable audit logs with 7-year retention, role-based access control with MFA, and automated compliance reporting. The fully air-gapped architecture eliminates third-party data processor risk entirely.