LLM.co — Private AI & custom AI developmentCall +1 (206) 844-1326All inference local

LLM.co · Private AI & Custom AI DevelopmentAir-gapped private AI

AI for networks with no route to the internet: classified enclaves, controlled unclassified environments and plant-floor OT. Models, software and updates arrive on signed, scanned media.

FIG. — Mainframe cabinetLLM.co

An air gap changes everything about how software is built and delivered. Nothing can phone home, download a model, fetch a package or send telemetry. Every dependency has to be inside the boundary on day one.

We build and test in a mirrored environment outside the gap, then deliver signed, reproducible bundles with checksums and a software bill of materials, ready for your transfer and scanning process.

NetworkNo outbound route required at any time
DeliverySigned, reproducible bundles with SBOM and checksums
TelemetryNone leaves the boundary; monitoring stays local
ProgramsBuilt to support CMMC, ITAR and agency ATO packages
StaffingCleared engineers available for some engagements
What we build

What this looks like in practice.

01GAP

Classified assistants

Search, summarization and drafting for enclaves that can never connect out.

02GAP

Controlled environments

Deployments for CUI and export-controlled data under CMMC and ITAR programs.

03GAP

Plant-floor AI

Maintenance and quality assistants on isolated OT networks.

04GAP

Field kits

Self-contained systems that travel and run fully offline.

What air-gapped AI requires

Air-gapped AI runs on a network with no route to the internet at any time. That rules out habits most AI software depends on. Nothing can download a model, pull a container, install a package, check a license server or send telemetry. Every model file, library and dependency has to be inside the boundary before the system starts.

Most commercial AI tools assume a live connection somewhere in the chain. An air-gapped LLM has to be built and tested for disconnected operation from the first day, which is why we treat it as its own discipline within private AI.

Where air-gapped AI is used

Each of these settings has its own transfer rules, hardware limits and accreditation process. We design around the ones you already follow, and pair the deployment with custom AI development so the application on top is built for offline use as well.

  • Classified enclaves where analysts need search, summarization and drafting over material that can never leave
  • Controlled unclassified and export-controlled environments under CMMC and ITAR programs
  • Operational-technology networks on plant floors, in substations and in control rooms
  • Field kits that travel and run fully offline

How we build and deliver across the gap

We start by mirroring the target environment outside the boundary, with the same operating system, GPU model, driver versions and security settings. All development and testing happens there. When a release is ready, we package the models, container images and dependencies into a reproducible bundle with checksums, signatures and a software bill of materials.

The bundle goes through your approved transfer process, whether that is a cross-domain solution or scanned removable media. Inside the boundary it installs with no network access. Model and software updates follow the same path on a schedule you set, so nothing inside ever reaches out for a download.

Hardware for an air-gapped LLM

Air-gapped systems often have to use hardware that is already accredited inside the boundary, or wait through a long approval to add more. We size models to what is already there first. Quantized and smaller open-weight models from the Llama, Qwen, Mistral and Gemma families can run on modest GPUs and still do useful search and drafting work.

Where new equipment is justified, we write vendor-neutral specs for servers with cards such as the L40S, RTX 6000, H100 or H200, including power and cooling requirements for the site. Field kits get the same treatment at a smaller scale.

Monitoring and governance inside the boundary

An air-gapped AI system still needs logs, alerts and access control, and all of it has to stay local. Users authenticate against the identity service inside the enclave. The gateway enforces roles and document permissions and records every prompt, retrieved passage, answer and action to the local log platform or SIEM. Dashboards for GPU use, latency and quality run inside the boundary, and no telemetry leaves it.

For authorization, LLM.co provides architecture, data-flow and control documentation to support your ATO package or CMMC assessment. Cleared engineers are available for some engagements. The authorization decision stays with your authorizing official.

How it works

Four steps, each one reviewed.

01

Mirror

Reproduce the target environment, including OS, hardware and policies, outside the gap.

02

Bundle

Models, containers and dependencies packaged with checksums, signatures and an SBOM.

03

Transfer

Delivered on media through your approved cross-domain or sneakernet process.

04

Update

Scheduled update bundles for models and software, never live downloads.

Questions

Common questions.

What is air-gapped AI?

Air-gapped AI is an AI system that runs on a network with no connection to the internet. The models, software, data and logs all live inside the boundary, and updates arrive on approved media. It is used in classified enclaves, controlled environments and isolated operational-technology networks.

Can a large language model run without internet access?

Yes. Open-weight models such as Llama, Qwen, Mistral and Gemma are files that run on local GPUs with no outside connection. The work is in packaging every dependency in advance, removing any component that tries to call out, and testing the full system in a mirrored disconnected environment before delivery.

How do model updates get into an air-gapped network?

As signed bundles on your approved media or cross-domain path, on a schedule you set. Each bundle includes checksums, signatures and a software bill of materials for your scanning process. Nothing inside the boundary downloads updates on its own.

What hardware does an air-gapped LLM need?

For focused tasks, often modest hardware. Quantized models can run on modest GPUs already inside the boundary. Larger models and many concurrent users need data-center GPUs such as the NVIDIA H100 or H200. We size to existing accredited hardware first and recommend new equipment only where the evaluation results call for it.

Can you support our ATO or CMMC assessment?

We provide architecture diagrams, data-flow diagrams, a software bill of materials and control documentation to support your authorization package or assessment. The authorization decision stays with your authorizing official, and certification stays with your assessor.

Does air-gapped AI work on older hardware?

Often, with smaller or quantized models. Older GPUs limit model size and speed, so we test candidate models on matching hardware in the mirrored environment and show you the evaluation scores before anything crosses the boundary.

Is an air-gapped AI system fully secure?

No system is fully secure. Removing the network route closes the remote paths most attacks rely on and keeps data away from vendors. Risk remains at the transfer point and with users inside, which we address with signed, scanned bundles, role- and document-level access, and full audit logging to your local SIEM, designed to fit your existing security controls.

Do your engineers hold security clearances?

Cleared engineers are available for some engagements. Where we cannot staff the clearance an engagement requires, we build and test in the mirrored environment and hand your cleared personnel installation runbooks and documentation for work inside the boundary.

Start here

Submit a job card.

Tell us the workflow and where the data lives. An engineer, not a salesperson, replies within one business day with a first take on architecture and cost.

Job cardLLM.CO · FORM 704-A
Practice
Where should it run?
Do not fold, spindle or mutilate