Skip to content
sDEN

Manufacturing knowledge

Private RAG inside your boundary

Run open-weight models and a knowledge graph inside your own boundary to protect industrial IP, and put permissions, evaluation and monitoring in place.

Private compute racks standing on a protected platform inside your own boundary
On this page

Drawings, process parameters, test data, supplier terms and quality history are some of the most valuable knowledge a manufacturer has. Much of it is proprietary, some of it is covered by customer agreements, and a great deal of it would interest competitors. Sending it to an external AI service so an assistant can answer questions about it is a decision many organizations are not willing to make.

They do not have to. Open-weight models can run inside an environment the organization controls, whether on premise, in a private cloud or in a hybrid setup, and a governed knowledge graph can hold the context those models read. Retrieval-augmented generation then happens entirely within the boundary.

Running AI privately is not only an infrastructure choice, though. Controls that a hosted service might provide, and several it does not, become the organization's responsibility. This piece covers what private RAG involves and what has to be in place for it to be trustworthy.

Why private

Control over data, models and operations

Private deployment answers a simple question: who can reach your knowledge, and under whose rules?

When documents and questions are processed by an external service, the protection of the organization's intellectual property depends on that provider's contracts, operations and jurisdiction. Where a provider is incorporated decides which law can reach the data, wherever the servers sit. For many industrial organizations, the knowledge in their engineering and quality archives is too important to place under someone else's control.

Private deployment keeps data where it already is. Documents stay in their repositories, the knowledge graph runs inside the boundary, and models run privately. Every request passes through one governed gateway that records what happened, so the organization knows which systems and people used which data.

It also keeps choices open. Open-weight models and open standards keep each layer replaceable. When a better model appears, it can be evaluated and adopted without rebuilding the data layer or renegotiating access to the knowledge.

The architecture

What runs inside the boundary

A private RAG system has the same layers as a hosted one. The difference is who operates each of them.

At the base are the data sources: file shares, PLM, the quality management system, ERP and document repositories, connected with their existing permissions. Above them sits the governed knowledge graph, which holds extracted entities, relationships, source locations, lineage, classifications and access rules, along with the passages used for search.

The model layer runs private open-weight models sized to the workloads, on compute the organization chooses, from its own data center to a private cloud. Extraction follows the same principle: OCR, models and deterministic methods run in the environment, so documents are never sent out to be read. A gateway sits in front of the models and applies identity, policy and logging to every request.

At the top are the applications and agents people use: assistants, search, and workflows with defined tools, approvals and limits. They reach knowledge only through the graph and models only through the gateway, which is what keeps the whole system governable.

What has to be in place

Permissions, evaluation, monitoring and an owning team

Private infrastructure without these is a private liability.

Permissions at query time come first. The assistant must retrieve only what the requesting user may see, enforced when the query runs and based on the permissions that already exist in the source systems. Running privately does not make this optional; internal over-exposure of sensitive knowledge is still a breach.

Evaluation and monitoring come next. A graded set of real questions, with expected answers and sources, should score retrieval and answer quality on every change to models, prompts or data. In production, monitoring watches retrieval quality, usage and cost per team, and the gateway's audit trail records every request. Without this, model upgrades and document changes can degrade quality silently.

Finally, a team has to own it. Private AI is a system to operate, not a product to install. Someone has to own the graph, the models, the evaluation set and incident response, with named owners and shared standards. Building that capability internally, often as an AI Center of Excellence, is what lets the organization keep running and evolving the stack after the initial deployment.

Models and capacity

Choose models by evaluation, size capacity by workload

Private deployment surfaces decisions that hosted services hide: which models, on what infrastructure, for which work.

Extraction, retrieval-grounded answering and agent workflows have different needs, and different models can serve each of them. The choice should come from evaluation on your own questions and documents, not from general reputation. A model that reads scanned tables well may not be the best one for summarizing quality history, and a smaller model may be enough for classification.

Capacity is sized to the expected use and shared across teams. Hosted AI bills every request; private capacity is paid for as compute, setup and operations, which favors consolidating workloads on one governed platform over letting each team run its own. Model licenses and infrastructure supplier terms still apply and belong in the plan from the start.

Because the graph carries the knowledge, changing a model is an evaluation exercise rather than a rebuild. The evaluation set shows whether a candidate model answers your questions better, the gateway makes the switch controllable, and the applications and data above and below the model stay as they are.

How sDEN approaches it

Private AI your teams can operate

sDEN deploys inside your environment, then transfers the capability so your teams can run it themselves.

Private AI your teams can operateExplore the perimeter

Within this scope

Inside your boundary

On premise, in a private cloud or hybrid: data stays where it is, models run privately, and every request passes through one governed gateway that records what happened.

Within this scope

Governed context, not raw access

sDEN Foundation gives private models source-linked context from a governed knowledge graph, with existing permissions enforced at query time.

Within this scope

Capability that stays with you

Evaluation, monitoring and operating knowledge are handed over, so your teams keep the data, the configuration and the knowledge to run and change every layer.

Illustrative map. Scope, responsibilities and controls are agreed for each engagement.

What good looks like

AI on your most sensitive knowledge, under your rules

The result is not just a private model. It is a system the organization can trust, explain and run.

Engineers and quality teams can ask questions of proprietary drawings, specifications and records without that knowledge leaving the environment. Answers cite their sources, and access follows the rules already in place.

Leaders can answer the questions that matter for governance: which AI systems run, what data they can reach, what they cost and who can stop them. The audit trail and a register of systems make those answers concrete rather than estimated.

Over time, private capacity can be shared by many teams and workloads instead of being billed per request, and the stack can change as models, hardware and needs evolve, because the data, the graph and the operating knowledge belong to the organization.

Questions

Manufacturing knowledge, answered.

What is private RAG?

Retrieval-augmented generation in which the documents, the retrieval layer and the models all run inside an environment the organization controls, whether on premise, in a private cloud or hybrid. Questions and documents are not sent to an external AI service.

Are open-weight models good enough for engineering and quality questions?

For retrieval-grounded questions, answer quality depends heavily on the context the model receives, and a governed knowledge graph with structured, source-linked data improves that context. The right model for each task should be chosen by evaluation on your own questions rather than assumed.

Do we need our own data center?

No. Private deployment can run on premise, in a private cloud or in a hybrid setup. The deciding factor is who controls the data, the keys, the contracts and the operations, which then shapes where each workload should run.

Who runs the system after deployment?

Your team. sDEN audits, designs and integrates, then transfers the capability, including evaluation sets, monitoring and operating knowledge, so the organization can operate and evolve the stack itself.

Does running privately remove the need for access control?

No. Permissions still have to be enforced at query time so each user only retrieves what they are allowed to see. Private deployment protects against external exposure; access control protects against internal over-exposure.

Ready to build AI you can govern, audit and own?

Discuss your data estate, institutional priorities and infrastructure requirements. Together, we can define the next decisions and the scope of a suitable engagement.

Private RAG on premise: keeping industrial intellectual property inside your boundary · sDEN