Where the agent runs
The agent harness may run on a workstation, server, container, Kubernetes environment, private virtual machine, or client-controlled cloud service. That location does not determine where the model runs.
AI Impact Maine helps organizations understand and control where AI-agent information is processed, transmitted, retained, logged, and stored. We design local, private-cloud, hybrid, and enterprise API architectures based on the organization’s data sensitivity, model requirements, infrastructure, and operating responsibilities.
This service is for Maine organizations evaluating private AI agents, secure enterprise AI, local AI agent deployment, isolated cloud AI agents, or direct commercial APIs while handling confidential business records, internal knowledge, operational data, or other sensitive information.
Information may still leave client-controlled infrastructure when an agent uses cloud-hosted AI models, external APIs, websites, search services, messaging platforms, SaaS applications, remote databases, third-party tools, or telemetry and logging services.
The agent harness may run on a workstation, server, container, Kubernetes environment, private virtual machine, or client-controlled cloud service. That location does not determine where the model runs.
A local model runs on client-controlled hardware. A private-cloud or direct enterprise model is processed by the selected cloud or model provider under its current service configuration and terms.
Conversation state, files, vector stores, logs, backups, tool results, and agent memory can each have different storage, retention, deletion, access, and regional-processing behavior.
It does not necessarily mean the provider never receives the request, no temporary processing occurs, no security or abuse-monitoring retention occurs, every feature qualifies for zero retention, or every external tool follows the same privacy policy.
AI Impact Maine can design and deploy an agent inside a client-controlled Microsoft Azure subscription, Amazon Web Services account, Google Cloud environment when appropriate, private hosted infrastructure, isolated virtual network, or hybrid on-premises and private-cloud environment.
A private or isolated cloud deployment reduces public exposure and gives the organization greater control over networking, identity, storage, and logging. It does not mean the cloud provider performs no processing, and it does not automatically guarantee that information never leaves the selected environment. Model endpoints, external tools, telemetry, backups, support features, and cross-region processing must all be reviewed.
The right design depends on data sensitivity, model quality, latency, hardware, integrations, operating skills, contractual terms, and which organization is prepared to maintain each layer.
Agent and model run on client-controlled hardware. Prompts can remain inside the organization when external tools are disabled. This can fit highly sensitive workflows but requires appropriate hardware, model-license review, hosting, updates, backups, monitoring, and security controls.
Use a client-controlled Azure, AWS, Google Cloud, or other private environment with private networking, identity controls, encrypted storage, retention review, and centralized logging. The model may be hosted privately or provided through an approved enterprise model service.
OpenAI or Anthropic receives the request to perform inference. Their current commercial documentation says business/API content is not used for model training by default, but default security or abuse-monitoring retention and feature-specific application state may still apply.
Zero Data Retention can require approval or a separate agreement. Eligibility depends on the organization, endpoint, model, feature, and contract. Stored conversations, files, assistants, background jobs, batches, and other stateful features can behave differently.
Sensitive source records can remain local while only the minimum necessary, redacted, or tokenized content is submitted for approved inference. Local retrieval can limit prompt contents, workflows can use different models, and higher-risk actions can require human approval.
| Architecture | Agent and model | Hardware and processing | Networking and exposure | Storage and retention | Operations and best fit |
|---|---|---|---|---|---|
| Fully local | Both run on client-controlled hardware. | Information can stay on company-controlled hardware if external services are disabled; the organization processes inference locally. | Can be isolated or allowlisted; public internet access is optional and should be minimized. | Organization controls memory, files, vector stores, logs, deletion, and backups. | Client or managed operator maintains hardware, model, patches, backup, and monitoring. Fits high-sensitivity bounded workflows with adequate capacity. |
| Private or isolated cloud | Agent runs in a client-controlled VPC/VNet; model is privately hosted or accessed through an approved enterprise endpoint. | Information leaves company-owned hardware for the client-controlled cloud. The cloud and model service process the request as configured. | Private endpoints, private DNS, no public inbound access, egress controls, allowlists, and identity policies are available. | Client controls agent memory and storage; model-service retention and feature behavior require verification. | Shared responsibility across client, implementation partner, and cloud provider. Fits enterprise cloud AI agents needing private networking and scalable operations. |
| Direct enterprise API | Agent runs under client control; provider-hosted model receives inference requests. | Content leaves company hardware and is processed by the contracted model provider. | Outbound encrypted API access; provider-side public service boundary and optional enterprise controls. | Default abuse-monitoring and application-state behavior varies; approved zero-retention controls are endpoint- and feature-specific. | Client operates the agent and provider operates the model. Fits teams prioritizing model capability and simpler infrastructure after contract review. |
| Hybrid local and private cloud | Agent, retrieval, and storage can remain local while approved content is routed to local or private-cloud models. | Only selected, minimized content leaves company hardware; local and cloud processors depend on routing. | Policy-based routing, private endpoints, outbound restrictions, and human approval for sensitive actions. | Sensitive source data stays local; cloud request retention still requires model- and feature-level review. | Client manages classification and local systems; cloud provider manages hosted services. Fits mixed-sensitivity workflows and phased modernization. |
On mobile, each architecture is displayed as a labeled card so every comparison field remains readable without horizontal scrolling.
These are planning summaries, not contractual promises. During every engagement, AI Impact Maine verifies the current official documentation and the client’s applicable terms for the chosen account, model, deployment type, region, API, feature, and tool.
Microsoft states that prompts and completions submitted to models sold through Azure are not available to OpenAI or other underlying model providers, and are not used to train foundation models without permission. Microsoft hosts and processes those models in Azure, and some stateful or safety features can store data. Global and DataZone deployments also affect where processing occurs.
AWS documents retention modes that can keep supported requests from durable storage or provider sharing, retain data within AWS, or permit provider sharing for models that require it. The selected model’s current allowed modes, region, cross-region inference, feature behavior, and account configuration must be checked before deployment.
OpenAI says API data is not used for training unless the customer opts in, while default abuse-monitoring logs can be retained and approved controls vary by endpoint and feature. Anthropic says standard API inputs and outputs are generally deleted within 30 days, subject to documented exceptions; separate approved zero-retention arrangements apply only to eligible products and organizations.
The model is only one part of the complete agent data path. A useful assessment follows information from its source through instructions, retrieval, inference, tools, storage, review, and recovery systems.
Control design connects the approved business purpose to the minimum data, identity, model, tools, memory, networking, logging, and human authority needed for the workflow.
AIM WorkAgent can be designed around client-approved business records, model routes, tools, and human review. AIM ConnectAgent adds approved web, messaging, gateway, or internal interfaces, so each channel and destination becomes part of the data-flow assessment.
AIM AgentGuard supports agent inventory, permissions and tool review, monitor-only logging review, activity auditing, governance, and remediation guidance where integrations and records are available. It does not replace endpoint security, DLP, identity security, network security, backups, legal review, or incident response.
Scope is confirmed before work begins. No prices are published because effort depends on data sensitivity, systems, providers, tools, operating model, documentation needs, and the selected deployment boundary.
Identify the owner, users, business outcome, sensitive information, decisions, approved actions, and prohibited actions.
Map the runtime, model, memory, storage, tools, identities, networks, logs, backups, sub-agents, and human interfaces.
Evaluate local, private-cloud, direct API, and hybrid designs against current documentation, contracts, capabilities, and operating capacity.
Configure one bounded architecture, validate flows and approvals, test failure and rollback, document ownership, and review residual risk.
AI Impact Maine provides technical assessment, architecture, implementation, documentation, staff handoff, and operational support. Engagement scope depends on supported systems, available documentation, access, logs, integrations, and the client’s operating responsibilities.
AI Impact Maine does not provide legal advice or compliance certification. Qualified legal, privacy, security, procurement, and compliance professionals should review applicable requirements and contracts.
It can be designed to keep approved prompts, models, memory, and storage on client-controlled infrastructure when external tools and cloud services are disabled. The complete workflow must still be reviewed because browsers, updates, telemetry, backups, messaging, and other connectors can create external data paths.
No. A local agent runtime can still send information to a cloud model, external API, website, search service, SaaS application, remote database, messaging platform, or logging service. Local runtime, local model, and local storage are separate architecture decisions.
Microsoft states that models sold through Azure are hosted in Microsoft's Azure environment and prompts and completions are not made available to OpenAI or other underlying model providers. Microsoft still processes the information to operate and protect the Azure service, and deployment type, enabled features, storage, abuse monitoring, and regional processing must be reviewed.
Amazon Bedrock can provide access to supported Claude models through AWS. AWS documentation says provider access and retention depend on the selected model and configured retention mode: some modes keep requests within AWS, while certain models or features can require provider data sharing. The current model's allowed modes must be verified before deployment.
No training generally addresses whether customer content is used to improve models. Zero data retention addresses whether eligible request and response content is stored after processing. Neither phrase by itself describes every log, safety control, stateful feature, external tool, backup, or contractual exception.
No. A hosted model provider must process the submitted content to perform inference. Zero-retention controls address storage after processing, subject to the provider's current documentation, approved controls, supported endpoints, features, contract, legal requirements, and safety exceptions.
Yes. A hybrid design can keep higher-sensitivity records and retrieval local while routing minimized, redacted, or lower-risk content to an approved private-cloud or enterprise API endpoint. Each route needs a documented data classification, permission boundary, logging plan, and human approval model.
It includes a business use-case review, data inventory and classification workshop, agent data-flow diagram, model and provider comparison, retention and logging review, tool and connector inventory, identity and permission review, human-approval recommendations, risk register, recommended architecture, implementation roadmap, written findings, and executive summary.
No. AI Impact Maine provides technical assessment, architecture, implementation, documentation, and operational support, not legal advice or compliance certification. The client and its qualified legal, privacy, compliance, and security advisers remain responsible for applicable requirements.
AIM AgentGuard can support approved environments with agent inventory, permission and tool review, logging-gap analysis, monitor-only activity review, selected session auditing, governance documentation, and remediation guidance. Coverage depends on supported integrations and available records, and it does not replace endpoint, identity, DLP, network, or incident-response controls.
Private Cloud AI Agent Deployment places the agent runtime, identity, storage, memory, and logging inside a client-controlled cloud account and isolated network, then connects only approved model endpoints and tools. It improves control over networking and operations but does not mean the cloud provider performs no processing or that every enabled service keeps data inside one environment.
Tell us what the agent needs to access, which models or cloud environments you are considering, and who must approve sensitive actions. Do not send confidential records through the contact form; we will establish scope before reviewing sensitive material.