Forward-Deployed Engineering06
We deploy the system inside the boundary your regulator and your security team already accept, with egress blocked at the network edge and every action attributed in your log store. Scoped per environment.
FDE / 01Three environments
Three places the system can run. The rules are the same in each; what changes is what has to be carried in.
Your account, your region, your identity provider. Models reached through private endpoints inside the provider's network, or self-hosted in your account. Egress blocked at the network edge; logs in your log store.
Your hardware, your network, your operations team. Open-weight models self-hosted on your GPUs; the gateway, the vector store and the audit log on machines you own. Updates arrive through the path your change control already uses.
An air-gapped enclave. Models, weights, dependencies and updates carried in on approved media; nothing carried out. The audit log is the only record that leaves, and only by your procedure.
Zero data egress, enforced at the edge and tested; every action attributed to a person; secrets in your vault; no standing access for us after handover. The environment changes; the rules do not.
FDE / 02Compared
Each is the right call for a different constraint. The table says what each gives and what it costs, so the choice is made on the row that matters to you.
| Criterion | Your cloud | On-premises | Air-gapped |
|---|---|---|---|
| Zero data egress | yes | yes | yes |
| Every action in your audit log | yes | yes | yes |
| Provider models through private endpoints | yes | no | no |
| Open-weight models self-hosted | yes | yes | yes |
| Updates arrive over the network | yes | yes | no |
| Runs on hardware you already own | no | yes | yes |
| Starts within weeks | yes | partial | no |
FDE / 03What you keep
6 ITEMS
Six things your security team signs before real records enter the system.
What may leave the perimeter, which is nothing but the audit log, written down, enforced at the network edge, with the test that proves it.
The system acts through your identity provider as the person it works for; each role, scope and revocation path documented.
Every model call, retrieval and write attributed, timestamped and stored in your log store, with the retention you set.
Credentials and keys in your vault, rotated by a procedure in the runbook, never in code or configuration.
One path to any model, inside the perimeter, that logs each call, strips what must not be sent and blocks what must not leave.
The threat model, your security team's findings, how each was closed, and the sign-off, dated.
FDE / 04Specified
10 FIELDS
The terms as they stand before the first call. The environment moves the detail; it does not move the rules.
FDE / 05Fit
FDE / 06Proof
2 ROWS
Illustrative engagements written end to end, chapter by chapter.
FDE / 07Questions
6 QUESTIONS
No record, prompt, embedding or telemetry leaves the boundary. The block is enforced at the network edge, not by a setting in code, and it is tested by attempting egress and recording the block. The audit log is the only thing that leaves, and only by your procedure.
Inside your cloud, yes, where your policy allows: through the provider's private endpoints, with the gateway logging every call and stripping what must not be sent. On premises or air-gapped, models are open-weight and self-hosted on your hardware.
Through the procedure you already use for approved media. Weights, dependencies and code are packaged, signed and carried in; the runbook describes the steps and your team performs them. Nothing is carried out except the audit log.
Your security team, at each step, and they sign the manifest before real records enter the system. We write the threat model and close the findings; the sign-off is theirs.
Scoped access for the engagement, through your identity provider, visible in your audit log like anyone else's. It is revoked at handover, and the manifest records the revocation.
Integration & Data Onboarding scopes the connectors and the data model; this engagement scopes the perimeter they run inside. The two are usually run together, and Managed Operations can keep the environment running afterwards.
FDE / ENDStart
Book a scoping call with your security lead in the room; you leave knowing which environment fits and what it takes.