Your Infrastructure
Squad runs on compute, storage, and networking that you own. AWS, Azure, GCP, private cloud, or on-premise bare metal.
Squad runs inside your environment as a managed enclave. We deploy, operate, and maintain the platform on your infrastructure. Your data never leaves your network. Your team never touches the platform internals.
Squad is deployed as a self-contained platform within your cloud account or on-premise infrastructure. We manage it remotely through a secure management channel. From your organisation’s perspective, Squad is a service that simply appears on your internal network.
Your Infrastructure
Squad runs on compute, storage, and networking that you own. AWS, Azure, GCP, private cloud, or on-premise bare metal.
Our Management
We deploy, configure, monitor, patch, backup, and update the platform. Your IT team is not responsible for Squad operations.
Data Sovereignty
All data remains within your network boundary. Nothing is transmitted externally. Meets the strictest residency and sovereignty requirements.
Same Platform
Identical capabilities to Squad Cloud. Same cognitive engine, same UI, same API surface. No feature compromises.
Dedicated deployment requires your organisation to provision a baseline environment. Our team specifies the requirements during scoping; your IT team provisions the resources.
| Requirement | Detail |
|---|---|
| Compute | Virtual machines or container hosts meeting our specification (CPU, RAM, disk) |
| Network | Internal DNS, load balancer or ingress, firewall rules for internal traffic |
| Identity provider | Your existing SSO (Azure AD, Okta, ADFS, etc.) with SAML/OIDC metadata |
| Management access | Secure channel for our operations team (VPN, bastion, or agreed remote access method) |
| GPU (optional) | If running local LLM inference rather than external API keys |
Once your environment is provisioned, we own the entire platform lifecycle.
| Responsibility | Detail |
|---|---|
| Deployment | Initial installation, configuration, and validation |
| Platform operations | Application deployment, scaling, configuration management |
| Database operations | Neo4j, PostgreSQL, Redis, object storage — provisioning, tuning, maintenance |
| AI/ML | LLM inference setup (local Ollama or external API), embedding models, NLP pipelines |
| Security | TLS configuration, encryption at rest, secret rotation, vulnerability patching |
| Monitoring | Health checks, alerting, proactive incident response |
| Updates | Coordinated with your change management process; tested and validated before rollout |
| Backups | Automated backups within your environment with agreed retention and recovery targets |
| Model management | Model updates, performance tuning, inference optimisation |
The same three interfaces as Squad Cloud — but all traffic stays on your internal network.
Your team accesses Squad via an internal URL (e.g., https://squad.internal.yourorg.com). Traffic routes through your internal load balancer or ingress. No external network dependency.
Squad federates to your internal identity provider. Authentication traffic stays within your network.
Documents and files enter Squad via the same REST API, UI, and CLI — all over your internal network.
Squad runs as an isolated workload within your network. Typical topologies:
| Model | Description |
|---|---|
| VPC / Subnet | Squad in a dedicated subnet within your cloud VPC, peered to your application and identity subnets |
| Private DNS | Internal DNS resolution for the Squad endpoint; no public DNS entry required |
| On-premise VLAN | Squad on a dedicated VLAN with firewall rules to your identity and data services |
| Air-gapped | Fully disconnected; updates delivered via secure media; no outbound connectivity |
Scoping
We assess your environment, compliance requirements, and infrastructure constraints. We provide a detailed specification for the compute, network, and access your team needs to provision.
Provisioning
Your IT team provisions the baseline environment to our specification. We provide validation scripts to confirm readiness.
Deployment
Our team deploys the Squad platform into your environment, configures SSO federation, sets up model inference, and validates end-to-end functionality.
Integration testing
We work with your team to validate network connectivity, identity federation, data ingestion, and user access. Any firewall or DNS adjustments are resolved here.
Data onboarding
Your team uploads initial data. We assist with ontology configuration and ingestion validation.
Handover
Training sessions for your team covering the platform UI, query workflows, the Tune page, and administration. Ongoing operations continue via our secure management channel.
| Squad Cloud | Dedicated | |
|---|---|---|
| Where it runs | Squad-managed infrastructure | Your cloud or on-premise |
| Data location | Squad infrastructure (your chosen region) | Your infrastructure |
| Network | Internet-accessible with SSO | Internal network only |
| Managed by | Squad | Squad |
| Setup time | Days | Weeks |
| Updates | Automatic | Coordinated with your change management |
| Air-gap capable | No | Yes |
| Best for | Fast evaluation, teams without strict residency | Regulated environments, sovereignty, air-gapped networks |
Ready to run Squad on your infrastructure? Contact our team to begin scoping your dedicated deployment.