Your people already use AI. The question is whose servers it runs on.
A private enterprise AI platform — deployed on your infrastructure, speaking your languages, governed by your rules, audited to your regulator’s standard. Frontier AI, inside your perimeter.
Built for regulated enterprises. On-prem · private cloud · sovereign cloud — full source-code ownership.
In one paragraph
Sphere Private AI Workspace is a private enterprise AI platform with a ChatGPT-class chat experience, deployed on your own infrastructure — on-premise, in your private cloud, or in an in-country sovereign cloud — so prompts, documents, and outputs never leave your jurisdiction. It combines Arabic and English chat with retrieval-augmented answers over your documents, configurable guardrails with prompt-injection detection, role-based access control with quotas, Entra ID single sign-on, a complete exportable audit trail, and open or frontier models served privately on vLLM. Built by Sphere Inc. for banks, insurers, and regulated enterprises, it reaches production in 8–12 weeks with full source-code ownership delivered to you.
Chapter01
The quiet breach
At 9:14 on a Tuesday morning, a credit analyst at a mid-size bank pastes three pages of a customer’s loan file into a free AI chatbot. She isn’t malicious. She’s busy. The tool is brilliant, the deadline is real, and the policy memo banning it is somewhere in her inbox, unread. By 9:15, confidential customer data is sitting on infrastructure her bank doesn’t own, in a jurisdiction her regulator has never approved, training a model she’ll never control.
This scene is playing out in every regulated institution on earth, every day. Security teams call it shadow AI. We call it what it actually is: unmet demand. Your best people have discovered the most powerful productivity tool of their careers, and the only version available to them is the one that leaks.
Banning AI doesn’t stop AI. It just stops you from seeing it.
The institutions winning this moment aren’t the ones with the strictest firewalls. They’re the ones who moved first to give their people something better than the public tools — inside the perimeter, on their terms.
78%
of knowledge workers admit using unapproved AI tools at work
1 in 5
enterprise data-loss incidents now involve a public AI tool
0
regulators who accept "we didn’t know" as a compliance posture
Chapter02
The false choice
Most institutions believe they have three options. All three lose.
Ban it
Block the domains, publish the policy, hope for the best. Usage goes underground, onto personal phones and home laptops — where you have zero visibility and zero logs.
Cost: the risk stays. The productivity leaves.
Allow public SaaS
Sign the enterprise tier of a public tool and accept that your prompts, documents, and customer data transit infrastructure outside your jurisdiction and your control.
Cost: data residency, auditability, regulator trust.
Build it yourself
Stand up open-source components internally. Eighteen months later you own a science project: no guardrails, no audit layer, no Arabic support, and the engineer who built it just resigned.
Cost: 18 months, seven figures, one resignation.
Chapter03
The third path
Sphere Private AI Workspace is the platform your team would have built with 21 years and 300 enterprise deployments behind them — delivered in weeks, owned by you.
ChatGPT-class experience
Clean, fast, familiar chat with folders, prompt library, edit-and-resend, stop generation, dark/light themes. Adoption without training.
Document intelligence
Upload and interrogate PDF, Office, CSV, JSON, logs, and images. Retrieval-augmented answers with citations to your own sources.
Arabic + English, natively
Full RTL interface, automatic language detection, bilingual RAG. Built for the Gulf, not translated for it.
Guardrails & moderation
Configurable input/output guardrails, prompt-injection detection, payment-card upload detection, real-time admin alerts on policy breaches.
Audit everything
Centralized audit database: every login, prompt, response, upload, and admin change — exportable to Excel for compliance, retained to your policy.
Admin command center
RBAC with role-based feature visibility, per-user and per-group quotas, rate limits, usage analytics, feedback metrics — full operational control.
Model-agnostic core
Qwen, Llama, or frontier models via private endpoints — served on vLLM, switchable per use case, upgraded without downtime.
Creates real work
Documents, presentations, spreadsheet analysis with charts, code with syntax highlighting. Voice input in Arabic and English. MCP-ready for what’s next.
We’ve read your RFP. Before you wrote it.
These are the requirements regulated buyers put in front of us — verbatim — and how the Workspace answers each one. Tap to expand.
Get the full template
16 sections, 24 “Why This Matters” notes built in — the same document our own solutions team uses before every private-LLM engagement. Free, unbranded, yours to keep.
- Instant delivery to your inbox
- No sales call required
- Editable — adapt it or hand it to procurement as-is
Chapter04
Inside the perimeter
Five layers. Zero external dependencies. Every one of them yours.
Deploy it where your regulator lives
On-premise
Your data center, your GPUs, air-gapped if required. We size the hardware with you — honestly, for your real concurrency.
Private cloud
Your VPC on AWS or equivalent, deployed by an AWS Premier Partner with frontier-model access via private endpoints.
Sovereign cloud
In-country platforms with full data-residency compliance for banking, government, and healthcare mandates.
You’re going to write this RFP anyway. Start from ours.
Generalized from a real private-LLM RFP issued by a regional bank, then reviewed line by line. 16 sections, 24 built-in “Why This Matters” notes, and the exact requirements regulated buyers use to separate real vendors from decks.
16
Requirement sections
24
"Why This Matters" notes
$0
Free, unbranded, yours to keep
Sample requirement, straight from the template
“Complete audit trail of every prompt, response, and file — exportable for compliance.” REQ 2.17, 5.2–5.4
Why this matters: vendors who can’t answer this in one sentence usually built logging as an afterthought — which means it breaks under audit, not during the demo.
Used internally by Sphere’s own solutions team before every private-LLM engagement.
Chapter05
Trust is earned in production
Sphere has spent 21 years shipping systems that regulated enterprises bet their operations on. The Workspace stands on that record.
21
years of enterprise engineering
300+
clients across 28 countries
NPS 75
client satisfaction that speaks for itself
Aviation · Document AI
60×
faster resolution across 35,000+ operational documents for a global air charter group — AI answers with citations, in production.
Financial services · RAG
6h → sec
Complex cross-border tax research that took specialists six hours, answered in seconds by a private retrieval system.
Read the case studyEnergy · Automation
$1.2M
annual savings from AI-driven back-office automation for an oil & gas accounting provider.
Read the case studyChapter06
The first ninety days
No eighteen-month transformation theater. A disciplined path from decision to production.
1
Diagnostic & architecture
Weeks 1–2. Use-case mapping, security review, model selection, honest hardware sizing for your real concurrency — not a padded bill of materials.
2
Deploy & harden
Weeks 3–8. Workspace deployed in your environment, SSO federated, guardrails configured, documents connected, penetration testing completed and cleared.
3
Launch & transfer
Weeks 9–12. Pilot cohort live, admin team trained hands-on, documentation and source code delivered, adoption metrics on your dashboard.
Start with the AI Opportunity Diagnostic
A fixed-fee, two-week engagement: your use cases ranked by ROI, a deployment architecture for your environment, and a business case your board can approve. Fully credited toward implementation.
Fixed fee · two weeksFully credited toward your build
Talk to us about the DiagnosticQuestions Buyers Ask Before the RFP Goes Out
What is a private AI workspace?
A private AI workspace is a private AI platform with a ChatGPT-class chat experience, deployed entirely on your own infrastructure — on-premise, in a private cloud, or in an in-country sovereign cloud — so prompts, documents, and model outputs never leave your jurisdiction or control. Sphere Private AI Workspace adds the enterprise layer: SSO, role-based access control, configurable guardrails, prompt-injection detection, and a complete audit trail of every interaction.
Can a bank deploy a ChatGPT alternative on-premise?
Yes. The Workspace runs containerized on Docker and Kubernetes in your data center or approved sovereign cloud, serves open models such as Qwen and Llama on vLLM (or frontier models via private endpoints), and meets banking requirements: TLS 1.3 in transit, AES-256 at rest, Entra ID SSO over SAML 2.0/OIDC, maker-checker patterns, exportable audit logs, penetration-test reports, and source-code escrow.
Does the platform support Arabic?
Yes — natively, not as an afterthought. Full Arabic and English interface with right-to-left (RTL) layout, automatic language detection, bilingual retrieval-augmented generation over Arabic and English documents, and Arabic/English speech-to-text voice input.
How long does deployment take?
A typical deployment reaches production in 8–12 weeks: weeks 1–2 for diagnostic and architecture, weeks 3–8 for deployment and hardening including penetration testing, and weeks 9–12 for pilot launch, hands-on admin training, and full documentation and source-code handover.
Who owns the source code and model artifacts?
You do. Sphere delivers full source code, deployment scripts, architecture and operations documentation, and hands-on knowledge transfer at project completion — with escrow arrangements available where procurement requires them.
Which AI models does the Workspace support?
The model layer is agnostic by design: open-weight models such as Qwen and Llama served on vLLM inside your environment, or frontier models accessed through private cloud endpoints. Administrators switch between model versions and sizes per use case, and upgrades deploy without downtime.
How does the platform prevent data leaks and prompt injection?
Governance is enforced at three layers: configurable guardrails on inputs and outputs, domain restriction of responses, detection of sensitive-data uploads such as payment-card information, and real-time admin notifications when policy boundaries or injection attempts are detected. Every event lands in the central audit database — exportable for your compliance team.
Does it integrate with our existing identity provider?
Yes — native federation with Microsoft Entra ID, Okta, Ping, or any SAML 2.0 / OAuth 2.0 / OIDC identity provider. For regulated buyers this is typically the first gate a vendor has to clear: no shadow identity system, no separate login to manage. If SSO isn’t day-one, most procurement teams won’t evaluate the rest of the proposal.
What does the audit trail actually capture?
Every authentication event, prompt, AI-generated response, file upload and download, session detail, and admin change — timestamped, attributable to a specific user, and exportable for your compliance and regulatory reporting. This is the single most-cited requirement across regulated-industry AI RFPs, and it’s asked twice in most of them: once functionally, once at the infrastructure level. We answer both the same way.
Can this run in our specific country or region, not just "the cloud"?
Yes, and we’ll name the specific facility. Data residency is usually the requirement that determines whether a vendor is even eligible to bid — a vague answer like "we support cloud deployment" doesn’t clear that bar. The Workspace deploys on-premise, in your private cloud, or in a named in-country/in-region sovereign cloud, aligned to your jurisdiction’s specific data protection law.
Do you have reference clients in our industry and region?
Yes — regulated buyers weight peer references (same industry, same region, comparable data-residency constraints) far more heavily than a general enterprise client list, and we answer accordingly with implementation case studies from comparable institutions rather than logo-count.
The analyst from Chapter One still has a deadline.
The only question is whether the AI she uses tomorrow is the one that leaks — or the one you gave her. Talk to a Sphere solutions architect this week: a 30-minute working session on your environment, your regulator, and your fastest safe path to production.
Not ready to talk? Download the Private Enterprise LLM RFP Template — the requirements document we wish every buyer started from. Free, unbranded, yours to use.
Talk to a solutions architect
Direct to a senior architect — never a sales queue. Replies within one business day.
By submitting, you agree to be contacted about this request. We never share your details.