Deployment
Air-gapped is often described as self-hosting with stricter rules. It is a different operating model, and the differences show up in places that are easy to miss until you are already committed.
Yaju Team · 17 March 2026
Some organisations cannot connect the systems that matter to anything outside. Defence, parts of critical infrastructure, certain research environments, some regulated financial functions. For them air-gapped is not a preference, it is the starting condition.
It works. It is also genuinely different, and we would rather set expectations properly than discover them together in month three.
The governance layer, entirely. Policy enforced at the moment of action. Credentials resolved at runtime from an organisation-level vault. Complete audit trail. Evals on every run. Spend attributed per agent.
We consider this non-negotiable. An isolated deployment with reduced governance would be the worst combination available: the environment with the highest accountability requirements running the least accountable version.
Updates arrive as artefacts rather than as a background process. Somebody moves them across the boundary, on a schedule, with verification. This is a routine your team owns and should design deliberately rather than improvise.
Diagnosis is local. When something behaves oddly, nobody outside can look. That means your own observability has to be good enough to answer questions unaided, and it means support conversations are conducted through descriptions rather than access.
Models are deployed artefacts. Changing one is a planned operation, not a configuration setting, which makes model selection a heavier decision than it is elsewhere. Build your evaluation set before you need it.
Capacity. In a connected deployment, growing usage is somebody else's scaling problem. In an isolated one it is yours, and agent workloads grow in a way that is hard to predict because usage follows confidence rather than a plan.
The pattern is consistent: comfortable in month one, tight in month six. Size for the growth curve, not the pilot.
A named owner per agent, because retrofitting ownership in an environment where you cannot query anything from outside is considerably more painful.
An evaluation set built from real cases, because model changes are heavy here and you will want them to be reversible decisions rather than leaps.
Budgets that block, because an isolated environment does not make overspending impossible, only less visible.
An update routine designed before the first update rather than during it.
If your constraints require it, the question is already answered and the work is to plan it properly.
If they do not, we would be honest that air-gapped operation costs real effort for a benefit you may not need. A self-hosted deployment inside your own infrastructure covers most residency and control requirements with considerably less operational overhead.
The deployment pages cover self-hosted and air-gapped options. The Trust Center covers residency and compliance, and specific constraints can go to contact@capconsultor.eu.