Managed Private AI

AI that arrives working.

Everything an AI platform team would build, delivered as a finished product: enterprise chat, retrieval over your own documents, and a private coding assistant. Run by your IT office the way it runs the rest of IT, and yours outright: your hardware, your cloud, your keys, one SLA.

01Working on day one 02Run by the IT team you have 03Your data stays yours 04One SLA
The Console

Run AI in the language you already speak.

Your IT team thinks in people, groups, and applications. The console works the same way, and translates the GPU physics for you:

  • People belong to groups and carry their own budgets and allowances.
  • Groups are permitted applications, and each application points at a model.
  • Granting access is free. Hosting a model occupies measured capacity. Consumption is metered per person. The console keeps the three apart.

Every action is a configuration change, versioned and signed, and every number on screen carries its provenance: measured, derived, or declared.

Governance & console →

Every company's AI stack is three layers. Freehold delivers all three, working together.

The models doing the work, the rules about who can use which model and how, and the applications employees actually open. Enterprises with a platform team weld those layers into something that fits them. Everyone else buys frontier seats one login at a time and lives with the terms attached. Freehold is the third option: all three layers, pre-assembled, delivered as a configured deployment.

Applications

What employees open on Monday

Enterprise chat and content creation, retrieval over your own corpus, and a private coding assistant in every developer's IDE. Finished, named applications from a growing catalog, working on day one.

Explore the catalog →
Governance

Rules your IT office actually controls

Who can use what, on which model, with what budget, and what leaves the building. A config-only console built for the administrator who already runs Google Workspace or M365.

See the console →
Models

A curated menu, kept current

The strongest open-weight models, each selected for a job and right-sized to your capacity, plus governed access to frontier providers under your own keys. Upgrades ship through the managed pipeline.

How the menu works →

One product, three places models can run.

The platform, your console, gateway, applications, and member memory, always runs under your control. The models are the layer that moves: each workload runs wherever its economics and constraints point, and can be moved later without a re-integration project.

On-premises

Your hardware, your building

Certified enterprise AI systems from Dell, HPE, or Lenovo, on your balance sheet, installed and operated under our SLA. The strongest sovereignty and the best economics at high sustained volume.

strongest sovereignty
Your cloud

A VPC in your name

GPU capacity rented in your own cloud tenancy. No capex, data stays in your tenancy. Don't have a cloud footprint? We stand one up in your name as part of onboarding.

control without a data center
Governed API

Frontier & open models, your keys

Third-party providers reached through your own governed gateway, under your own keys, with per-person budgets and a content-free audit. Start today, no procurement cycle.

fastest start

Mixing postures is the point. One group's chat can run on a local model while another group's runs against a frontier provider under your key with an allowance, falling back to the local model when it's spent. Moving a workload between postures changes where its model runs and nothing else.

Deployment postures in detail →
Sovereignty

Your data stays inside your perimeter, and the system is built to prove it.

Where data does cross a boundary, the crossing is explicit, permitted, and labelled. Three properties carry that promise:

  • One control path: every change is versioned, signed configuration, reconciled by a proven GitOps engine. Drift is detected and reverted, and the audit trail is the change history.
  • Structural separation: we operate the control plane and are architecturally unable to read prompts, documents, or weights. The same constraint contractually binds our subcontractors.
  • Fault-proven enforcement: every control is deliberately broken in testing, shown to fail visibly, and shown to recover cleanly before we claim it.
Security & sovereignty in detail →
Your perimetercrossings are labelled
Applications & member memory
Prompts, documents, retrieval corpus — stays inside
Yours
Governed gateway
Identity · budgets · egress policy · content-free audit
Every call passes through
Permitted crossings only
Third-party models under your key · whitelisted lookups · each logged
Governed egress

How buying works.

A configured deployment that arrives working. The operational machinery stays on our side, and your team gets a product they can run from day one.

Configure

Select applications from the catalog, models from the curated menu, and the posture mix that fits your constraints. A deployment is a selection from a fixed catalog, which is what makes it fast.

Bounded onboarding

A fixed-scope engagement: identity federation with your IdP, corpus ingestion for retrieval, hardware install where your posture includes it. No open-ended integration project, no platform team required on your side.

Operated, under one SLA

We run the platform and gate every update, and hardware vendors deliver field service as our subcontractors. You hold one SLA with one accountable party, and the catalog keeps growing while you run.

What a deployment includes →
Early access

Selecting early deployment partners.

The governance core is built and fault-tested. We're working with a small number of design partners, with priority for regulated industries and teams that will push the catalog hardest.