Skip to content

Self-hosted AI infrastructure for AWS

Enterprise AI that respects your permissions and proves it works.

TA Msev runs retrieval and evaluation inside your own AWS account. Answers only draw from documents the user can already open. Every prompt, model, or retrieval change is tested in CI before it ships.

  • Deploys in your VPC
  • No data egress
  • Billed through AWS Marketplace
retrieval traceExample · illustrative data

Ask as

query
"What is the escalation policy for payments incidents?"
user
alice@example.com
groups
sre-payments, all-staff

candidates 4 → authorized 3 → sent to model 3

  • confluenceSRE/Payments escalation runbookacl: sre-payments
  • gdriveOn-call rotation Q4.xlsxacl: sre-payments
  • s3policies/incident-response.pdfacl: all-staff
  • confluenceLEGAL/Payments disclosure planacl: legal

result Answer cites 3 documents. 1 filtered before generation.

The problem

Why most enterprise RAG pilots stall

Internal AI search usually works in the demo. It stops at security review, or it ships and nobody can tell whether the next change helped or hurt.

  1. 01 / access

    Retrieval ignores permissions.

    A typical RAG pipeline indexes every document into one vector store. Any user can then surface HR files, board material, or customer contracts they could never open directly. Security review stops the project, and it should.

  2. 02 / duplication

    Fixing it means a second permission model.

    Teams try to patch leaks with access rules inside the AI app. Now two systems must agree on who can see what, and they drift the first time someone changes a Confluence space or a Drive share.

  3. 03 / quality

    No one can say if a change made it better.

    A prompt edit fixes one question and quietly breaks ten others. Without a fixed test set and a gate in CI, every change ships on intuition and users find the regressions first.

Products

Two products. Use one or both.

Each deploys on its own. Together, retrieval changes are tested against the same permissions your users have.

Permission-aware RAG appliance

Clearance

Syncs S3, Confluence, and Google Drive together with each document's access list. At query time, retrieval is filtered to what the asking user can already see, before any text reaches the model.

  • Source permissions preserved on every sync
  • Filtering happens at retrieval, not in the prompt
  • Runs as containers in your VPC

indexed chunk metadata · example

source: confluence://SRE/payments-runbook
acl:   [group:sre-payments, user:cto@example.com]
synced: 2026-09-30T14:02Z

Read how it works

LLM evaluation and regression harness

Baseline

Runs golden test sets against every prompt, model, or retrieval change. Reports results on the pull request and fails the check when a metric drops below your threshold.

  • GitHub Actions and GitLab CI
  • Accuracy, groundedness, hit rate, latency, cost per query
  • Works with any LLM app; pairs natively with Clearance

PR check · example

✓ accuracy      0.91  ≥ 0.88
✗ groundedness  0.84  < 0.90
→ merge blocked

Read how it works

How it works

Permissions travel with the data. Quality is checked on every change.

01

Sources

your systems

S3 bucketsConfluenceGoogle Drive

Your AWS account · VPC

02

ACL-aware index

docs + principals

chunk → embeddingacl: group:sre-paymentsencrypted with your KMS key

03

Retrieval

identity-filtered

identity ← your IdP (SSO)filter → rank → citemodel endpoint you configure

04

Eval gate

in your CI

golden test set✓ pass → merge✗ regress → block
Data path from source systems to answers. Everything inside the dashed boundary runs in your AWS account.
  1. 01

    Sync documents with their permissions

    Connectors read documents and their access lists from S3, Confluence, and Google Drive. When a share or restriction changes at the source, the next sync updates the index.

  2. 02

    Index inside your account

    Each chunk is stored with the users and groups allowed to read it. The index, embeddings, and sync state live in your VPC.

  3. 03

    Filter by identity, then retrieve

    The user signs in through your identity provider. Retrieval filters on their identity before ranking, so unauthorized text never reaches the model.

  4. 04

    Gate every change in CI

    Changes to prompts, models, or retrieval run against your golden test set. If a metric falls below its threshold, the check fails and the merge is blocked.

Security and deployment

Built to be approved by your security team.

The deployment model is the security model. Nothing leaves your account, and every answer can be traced to the documents behind it.

  • Runs in your VPC

    Containers deploy into your AWS account. You own the network, the instances, and the data stores.

  • No data egress to us

    Documents, embeddings, queries, and logs stay in your account. Model calls go to endpoints you configure.

  • SSO and group-based access

    Sign-in through your identity provider over SAML or OIDC. Group membership drives retrieval filters.

  • Audit log for every query

    Each request records the user, the documents considered, the ones filtered out, and why.

  • Encryption with your keys

    Data at rest is encrypted with AWS KMS keys you control. TLS in transit between all components.

Read the security overview
audit-log · one queryExample
{  "ts": "2026-09-30T14:07:21Z",  "event": "retrieval.query",  "user": "alice@example.com",  "groups": ["sre-payments", "all-staff"],  "candidates": 4,  "authorized": 3,  "filtered": [    {      "doc": "confluence://LEGAL/payments-disclosure",      "reason": "no_matching_principal"    }  ],  "cited": [    "confluence://SRE/payments-runbook",    "s3://policies/incident-response.pdf"  ],  "request_id": "q_7f3a9c21"}

Audit events write to CloudWatch Logs or S3 in your account, in a format your SIEM can ingest.

Buying

Buy through AWS Marketplace.

Use the procurement path you already have. No new vendor onboarding for most AWS customers.

View on AWS Marketplace
  • Counts toward your AWS commit

    Eligible AWS Marketplace purchases can draw down an existing AWS spend commitment, subject to the terms of your agreement.
  • One bill

    Charges appear on your AWS invoice. No new vendor record, payment setup, or separate renewal cycle.
  • Standard contract terms

    Procurement can use the Standard Contract for AWS Marketplace instead of negotiating a new MSA.
  • Private offers

    Custom pricing, term length, and payment schedules are available through AWS Marketplace private offers.

From subscription to first query

  1. 1

    Subscribe

    Accept the offer in AWS Marketplace from the account that will run it.

  2. 2

    Deploy

    Launch the containers into your VPC from the provided deployment template.

  3. 3

    Connect

    Add your identity provider and your first source. Initial sync starts immediately.

See it run against your own permissions.

Book a session with an engineer. We walk through deployment in your account, ACL sync for your sources, and a CI gate on a test set you choose.