Sphere Partners
Sphere Private AI Workspace · Enterprise Private AI Platform

Your people already use AI. The question is whose servers it runs on.

A private enterprise AI platform — deployed on your infrastructure, speaking your languages, governed by your rules, audited to your regulator’s standard. Frontier AI, inside your perimeter.

4.9/5 Clutch Rating21 Years of Delivery Experience

Built for regulated enterprises. On-prem · private cloud · sovereign cloud — full source-code ownership.

In one paragraph

Sphere Private AI Workspace is a private enterprise AI platform with a ChatGPT-class chat experience, deployed on your own infrastructure — on-premise, in your private cloud, or in an in-country sovereign cloud — so prompts, documents, and outputs never leave your jurisdiction. It combines Arabic and English chat with retrieval-augmented answers over your documents, configurable guardrails with prompt-injection detection, role-based access control with quotas, Entra ID single sign-on, a complete exportable audit trail, and open or frontier models served privately on vLLM. Built by Sphere Inc. for banks, insurers, and regulated enterprises, it reaches production in 8–12 weeks with full source-code ownership delivered to you.

Chapter01

The quiet breach

At 9:14 on a Tuesday morning, a credit analyst at a mid-size bank pastes three pages of a customer’s loan file into a free AI chatbot. She isn’t malicious. She’s busy. The tool is brilliant, the deadline is real, and the policy memo banning it is somewhere in her inbox, unread. By 9:15, confidential customer data is sitting on infrastructure her bank doesn’t own, in a jurisdiction her regulator has never approved, training a model she’ll never control.

This scene is playing out in every regulated institution on earth, every day. Security teams call it shadow AI. We call it what it actually is: unmet demand. Your best people have discovered the most powerful productivity tool of their careers, and the only version available to them is the one that leaks.

Banning AI doesn’t stop AI. It just stops you from seeing it.

The institutions winning this moment aren’t the ones with the strictest firewalls. They’re the ones who moved first to give their people something better than the public tools — inside the perimeter, on their terms.

78%

of knowledge workers admit using unapproved AI tools at work

1 in 5

enterprise data-loss incidents now involve a public AI tool

0

regulators who accept "we didn’t know" as a compliance posture

Chapter02

The false choice

Most institutions believe they have three options. All three lose.

Option A

Ban it

Block the domains, publish the policy, hope for the best. Usage goes underground, onto personal phones and home laptops — where you have zero visibility and zero logs.

Cost: the risk stays. The productivity leaves.

Option B

Allow public SaaS

Sign the enterprise tier of a public tool and accept that your prompts, documents, and customer data transit infrastructure outside your jurisdiction and your control.

Cost: data residency, auditability, regulator trust.

Option C

Build it yourself

Stand up open-source components internally. Eighteen months later you own a science project: no guardrails, no audit layer, no Arabic support, and the engineer who built it just resigned.

Cost: 18 months, seven figures, one resignation.

Chapter03

The third path

Sphere Private AI Workspace is the platform your team would have built with 21 years and 300 enterprise deployments behind them — delivered in weeks, owned by you.

ChatGPT-class experience

Clean, fast, familiar chat with folders, prompt library, edit-and-resend, stop generation, dark/light themes. Adoption without training.

Document intelligence

Upload and interrogate PDF, Office, CSV, JSON, logs, and images. Retrieval-augmented answers with citations to your own sources.

Arabic + English, natively

Full RTL interface, automatic language detection, bilingual RAG. Built for the Gulf, not translated for it.

Guardrails & moderation

Configurable input/output guardrails, prompt-injection detection, payment-card upload detection, real-time admin alerts on policy breaches.

Audit everything

Centralized audit database: every login, prompt, response, upload, and admin change — exportable to Excel for compliance, retained to your policy.

Admin command center

RBAC with role-based feature visibility, per-user and per-group quotas, rate limits, usage analytics, feedback metrics — full operational control.

Model-agnostic core

Qwen, Llama, or frontier models via private endpoints — served on vLLM, switchable per use case, upgraded without downtime.

Creates real work

Documents, presentations, spreadsheet analysis with charts, code with syntax highlighting. Voice input in Arabic and English. MCP-ready for what’s next.

We’ve read your RFP. Before you wrote it.

These are the requirements regulated buyers put in front of us — verbatim — and how the Workspace answers each one. Tap to expand.

Standard, day one. Native Entra ID federation over SAML 2.0 and OAuth 2.0/OIDC, 2FA via authenticator, SMS, or email, configurable session timeout and inactivity logout, brute-force lockout with admin-console unlock.

Your infrastructure, your geography. Containerized on Docker and Kubernetes, deployable on your data center, your private cloud, or approved sovereign clouds. Every byte — prompts, documents, embeddings, logs — stays where your regulator can see it.

Governed by design. Policy-based guardrails at the input, retrieval, and output layers; domain restriction (e.g., banking-only responses); PCI-pattern detection on uploads; in-app admin notifications the moment a policy boundary is tested.

Evidence, not assurances. A centralized audit store records authentication events, prompts, model outputs, uploads, downloads, session details, and admin changes — queryable by user, date, and event type, exportable to Excel, auto-generated as daily reports.

You own the asset. Full source-code handover, deployment scripts, architecture and operations documentation, hands-on knowledge transfer for your IT team, and escrow arrangements where required. No black boxes, no hostage licensing.

Architected for the next five years. MCP support is native to the platform, and agentic orchestration, knowledge-base connectors, and enterprise-system integrations activate on the same foundation as licensed capability upgrades — no rip-and-replace, ever.
Free download

Get the full template

16 sections, 24 “Why This Matters” notes built in — the same document our own solutions team uses before every private-LLM engagement. Free, unbranded, yours to keep.

  • Instant delivery to your inbox
  • No sales call required
  • Editable — adapt it or hand it to procurement as-is

Chapter04

Inside the perimeter

Five layers. Zero external dependencies. Every one of them yours.

Experience layerWeb chat · AR/EN RTL · voice · mobile-ready
Governance layerGuardrails · moderation · RBAC · quotas
Knowledge layerRAG · vector store · document pipeline · citations
Model layervLLM inference · Qwen / Llama / frontier · hot-swap
Infrastructure layerKubernetes · GPU scheduling · HA/DR · your metal

Deploy it where your regulator lives

On-premise

Your data center, your GPUs, air-gapped if required. We size the hardware with you — honestly, for your real concurrency.

Private cloud

Your VPC on AWS or equivalent, deployed by an AWS Premier Partner with frontier-model access via private endpoints.

Sovereign cloud

In-country platforms with full data-residency compliance for banking, government, and healthcare mandates.

TLS 1.3 in transitAES-256 at restSAML 2.0 / OIDC SSOOWASP-alignedISO 27001 · SOC 2 practicesPen-test report includedHA / DR readySource code delivered
Free download · no sales call required

You’re going to write this RFP anyway. Start from ours.

Generalized from a real private-LLM RFP issued by a regional bank, then reviewed line by line. 16 sections, 24 built-in “Why This Matters” notes, and the exact requirements regulated buyers use to separate real vendors from decks.

16

Requirement sections

24

"Why This Matters" notes

$0

Free, unbranded, yours to keep

Sample requirement, straight from the template

“Complete audit trail of every prompt, response, and file — exportable for compliance.” REQ 2.17, 5.2–5.4

Why this matters: vendors who can’t answer this in one sentence usually built logging as an afterthought — which means it breaks under audit, not during the demo.

Get the free RFP template

Used internally by Sphere’s own solutions team before every private-LLM engagement.

Chapter05

Trust is earned in production

Sphere has spent 21 years shipping systems that regulated enterprises bet their operations on. The Workspace stands on that record.

21

years of enterprise engineering

300+

clients across 28 countries

NPS 75

client satisfaction that speaks for itself

Aviation · Document AI

60×

faster resolution across 35,000+ operational documents for a global air charter group — AI answers with citations, in production.

Financial services · RAG

6h → sec

Complex cross-border tax research that took specialists six hours, answered in seconds by a private retrieval system.

Read the case study

Energy · Automation

$1.2M

annual savings from AI-driven back-office automation for an oil & gas accounting provider.

Read the case study
AWS Premier PartnerAnthropic PartnerPrecision-Driven Engineering™Delivery: US · EU · MENA

Chapter06

The first ninety days

No eighteen-month transformation theater. A disciplined path from decision to production.

1

Diagnostic & architecture

Weeks 1–2. Use-case mapping, security review, model selection, honest hardware sizing for your real concurrency — not a padded bill of materials.

2

Deploy & harden

Weeks 3–8. Workspace deployed in your environment, SSO federated, guardrails configured, documents connected, penetration testing completed and cleared.

3

Launch & transfer

Weeks 9–12. Pilot cohort live, admin team trained hands-on, documentation and source code delivered, adoption metrics on your dashboard.

Start with the AI Opportunity Diagnostic

A fixed-fee, two-week engagement: your use cases ranked by ROI, a deployment architecture for your environment, and a business case your board can approve. Fully credited toward implementation.

Fixed fee · two weeksFully credited toward your build

Talk to us about the Diagnostic

Questions Buyers Ask Before the RFP Goes Out

What is a private AI workspace?

A private AI workspace is a private AI platform with a ChatGPT-class chat experience, deployed entirely on your own infrastructure — on-premise, in a private cloud, or in an in-country sovereign cloud — so prompts, documents, and model outputs never leave your jurisdiction or control. Sphere Private AI Workspace adds the enterprise layer: SSO, role-based access control, configurable guardrails, prompt-injection detection, and a complete audit trail of every interaction.

Can a bank deploy a ChatGPT alternative on-premise?

Yes. The Workspace runs containerized on Docker and Kubernetes in your data center or approved sovereign cloud, serves open models such as Qwen and Llama on vLLM (or frontier models via private endpoints), and meets banking requirements: TLS 1.3 in transit, AES-256 at rest, Entra ID SSO over SAML 2.0/OIDC, maker-checker patterns, exportable audit logs, penetration-test reports, and source-code escrow.

Does the platform support Arabic?

Yes — natively, not as an afterthought. Full Arabic and English interface with right-to-left (RTL) layout, automatic language detection, bilingual retrieval-augmented generation over Arabic and English documents, and Arabic/English speech-to-text voice input.

How long does deployment take?

A typical deployment reaches production in 8–12 weeks: weeks 1–2 for diagnostic and architecture, weeks 3–8 for deployment and hardening including penetration testing, and weeks 9–12 for pilot launch, hands-on admin training, and full documentation and source-code handover.

Who owns the source code and model artifacts?

You do. Sphere delivers full source code, deployment scripts, architecture and operations documentation, and hands-on knowledge transfer at project completion — with escrow arrangements available where procurement requires them.

Which AI models does the Workspace support?

The model layer is agnostic by design: open-weight models such as Qwen and Llama served on vLLM inside your environment, or frontier models accessed through private cloud endpoints. Administrators switch between model versions and sizes per use case, and upgrades deploy without downtime.

How does the platform prevent data leaks and prompt injection?

Governance is enforced at three layers: configurable guardrails on inputs and outputs, domain restriction of responses, detection of sensitive-data uploads such as payment-card information, and real-time admin notifications when policy boundaries or injection attempts are detected. Every event lands in the central audit database — exportable for your compliance team.

Does it integrate with our existing identity provider?

Yes — native federation with Microsoft Entra ID, Okta, Ping, or any SAML 2.0 / OAuth 2.0 / OIDC identity provider. For regulated buyers this is typically the first gate a vendor has to clear: no shadow identity system, no separate login to manage. If SSO isn’t day-one, most procurement teams won’t evaluate the rest of the proposal.

What does the audit trail actually capture?

Every authentication event, prompt, AI-generated response, file upload and download, session detail, and admin change — timestamped, attributable to a specific user, and exportable for your compliance and regulatory reporting. This is the single most-cited requirement across regulated-industry AI RFPs, and it’s asked twice in most of them: once functionally, once at the infrastructure level. We answer both the same way.

Can this run in our specific country or region, not just "the cloud"?

Yes, and we’ll name the specific facility. Data residency is usually the requirement that determines whether a vendor is even eligible to bid — a vague answer like "we support cloud deployment" doesn’t clear that bar. The Workspace deploys on-premise, in your private cloud, or in a named in-country/in-region sovereign cloud, aligned to your jurisdiction’s specific data protection law.

Do you have reference clients in our industry and region?

Yes — regulated buyers weight peer references (same industry, same region, comparable data-residency constraints) far more heavily than a general enterprise client list, and we answer accordingly with implementation case studies from comparable institutions rather than logo-count.

Epilogue

The analyst from Chapter One still has a deadline.

The only question is whether the AI she uses tomorrow is the one that leaks — or the one you gave her. Talk to a Sphere solutions architect this week: a 30-minute working session on your environment, your regulator, and your fastest safe path to production.

Not ready to talk? Download the Private Enterprise LLM RFP Template — the requirements document we wish every buyer started from. Free, unbranded, yours to use.

Talk to a solutions architect

Direct to a senior architect — never a sales queue. Replies within one business day.

By submitting, you agree to be contacted about this request. We never share your details.