PrivacyPal Cloud · Sovereign deployment

The sovereign AI governance plane. In your VPC. On your terms.

Cloud is the enterprise tier for organizations that demand full data sovereignty. A self-hosted AI governance gateway plus the first network-grade DSPM built for the AI data layer — across databases, lakes, RAG, vector and agent memory. Lives in your VPC. Air-gap ready. Zero-knowledge by design.

# Install on any desktop or server in your network
$ curl -sSL https://get.privacypal.ai | sh

# That's it. Every AI agent running on this machine
# is now protected by PrivacyPal Cloud.

$ privacypal status
✓ Gateway running on 127.0.0.1:7878
✓ Watching 4 local AI processes
✓ Routing through privacypal.yourco.internal
✓ 0 prompts left this network
The deployment checklist

Sovereign by design. Drop in anywhere your workloads live.

Zero code changes

Installs on the host and intercepts AI traffic at the network edge. Existing agents, copilots and SDKs keep their config — every request is twin-swapped on the way out.

AWS · Azure · GCP · bare metal

Terraform, Helm chart, or single-container deploy. Production-ready in an afternoon. Lives inside your tenancy — no third-party DPAs.

Air-gapped option

Run detection with on-prem models. No outbound traffic. Built for the regulated enterprise — Healthcare, FSI, Defense, B2B Tech.

Provider-agnostic gateway

OpenAI / Anthropic / Google compatible. Route to GPT, Claude, Gemini, Mistral, Llama or your own fine-tune. Switch per request.

Streaming-safe

Detects and swaps mid-stream without breaking token-by-token response. Users never see a hitch. Throughput-grade for production.

Horizontal scale & 24/7 SLA

Stateless workers. Scale to 100k req/s. P99 latency under half a second. Dedicated solution engineer. 24/7 support included.

Included with Cloud · Network DSPM

A full network-grade DSPM stack. Purpose-built for the AI data layer.

Cloud doesn't just protect AI traffic in motion. The same install gives you continuous discovery, classification, risk prioritization and remediation across every data store that feeds your models — databases, lakes, RAG pipelines, vector stores, agent memory. Pair it with Max's on-device DSPM and you have governance across the entire data surface — endpoints to enterprise data plane.

Agentless discovery

Connect a data store and it's in the scan queue. SQL Server, PostgreSQL, MongoDB, Supabase, Drive, OneDrive, Dropbox, object storage — read in place, no agents, no re-architecture, no performance hit.

Context-aware classification

The same intelligence that powers Privacy Twins reads your data the way a human would. PII, PHI, financials, proprietary schemas — surfaced across structured and unstructured stores. No regex to maintain, no rule sprawl.

Risk that's actually risk

Sensitivity tied to access patterns, exposure, and business purpose. A customer SSN in a public bucket is critical; a fixture in a dev database is not. Your team stops chasing noise and starts moving the needle.

One-click remediation

Revoke access, mask columns, kick off a workflow, or route findings to the data owner with full context. Discovery without remediation is a report nobody reads — Cloud closes the loop.

RAG, vector & agent memory

Scan the AI data layer the way you scan the database layer: vector stores, RAG pipelines, graph databases, agentic memory. Where your models read from — and where sensitive data quietly leaks in.

Sovereign by design

Scans run inside your network, against the same gateway already protecting your AI traffic. Findings, classifications, and remediation actions never leave your tenancy.

"We shipped an AI assistant on patient records in six weeks. Legal signed it in two days. That's PrivacyPal Cloud."
— CTO, healthcare SaaS · Series B

Your VPC.
Your keys. Your governance.

Stop choosing between AI velocity and data sovereignty. PrivacyPal Cloud lets you ship AI features your security team reviews in days, not quarters. Install once. Run sovereign.

Book a demo. View docs