Skip to content
Garnet

Building a private AI, or commissioning one.

An honest build-vs-buy for confidential work.

If you want a private, on-premise AI for confidential work, you have two honest paths: assemble one yourself from open-source parts, or commission a build that is designed, installed, and stood behind end to end. Both are legitimate. The right answer depends on the engineering you have in-house and how much of the upkeep you want to own.

What rolling your own actually takes

The building blocks are real and genuinely capable. You would choose an open-source model, stand up a serving runtime, quantize it to fit your hardware, wire up prompt and retrieval tooling, and size and source the hardware to carry it. None of that is the hard part. The hard part is turning that stack into a system you would stake privileged work on: hardening the network so nothing phones home, getting the offline boundary genuinely right, tuning it to your workload, and keeping it patched by hand without ever reopening the outbound path. And then keeping it all working after the person who built it moves on.

Where self-hosted setups leave gaps

Most do-it-yourself private-AI setups are secure enough for a demo and subtly wrong for confidential work. A stray telemetry setting, an auto-update that reaches out, a logging path that writes more than you think, a serving default that opens a port: any one of them quietly reintroduces the exact exposure you set out to remove. A sealed, network-isolated boundary is easy to get almost right, and "almost" is not a property you can promise a court, a regulator, or a client.

What a commissioned build adds

A commissioned build hands you the finished, hardened result instead of the parts. One accountable firm designs it, installs it, tunes it, and stands behind it, so when it matters you call one number rather than debugging it alone. It is network-isolated by default, can be deployed fully air-gapped where the setting calls for it, and it keeps working after handover with no standing access for anyone, including the firm that built it.

When each makes sense

If you have the in-house engineering to size, secure, and maintain a private AI, and the appetite to own that work indefinitely, rolling your own can absolutely be the right call. When confidentiality is non-negotiable and no one on staff owns the upkeep, a commissioned build usually earns its price, because the cost that matters is not the hardware, it is the sealed boundary being right every day and someone being accountable for it.

For the side-by-side, see the honest comparison of commissioning a build versus rolling your own, the plain-English guide to what a private AI is, and exactly what we can and can't see. A Garnet build is a private AI installed on a dedicated system in your building; for teams, see on-premise AI for law firms and in-house teams.

Design my Garnet →

Commissioned; scoped and priced individually. A conversation, not a checkout.