Where the hardware sits
At the customer site—normally in a locked server room, network closet, or controlled IT space with appropriate power, cooling, and physical access. The final location belongs to the customer’s facility and security plan.
Deployment & security
SkilakSpool is placed inside the customer’s physical and network environment. We work with IT, security, and business owners to define who can connect, from where, through which controls, and for what purpose.
Physical placement and access
The precise answer is site-specific, but the governing pattern is consistent: customer premises, private networks, approved identities, and no unmanaged remote path.
At the customer site—normally in a locked server room, network closet, or controlled IT space with appropriate power, cooling, and physical access. The final location belongs to the customer’s facility and security plan.
Only customer-authorized users and administrators. Ordinary use and privileged administration follow separate access roles, with enterprise identity integration where required.
Through the customer’s managed remote-access path: typically a managed device, MFA, and VPN or zero-trust network access. Skilak does not expose the AI interface directly to the public internet.
Reference architecture
This is the default logical pattern. The actual VLANs, hostnames, ports, identity flows, update path, logging, and support access are documented in the customer design.
Authorized users
Customer-controlled site
Approved network boundaryOptional, approved egress only
Delivery lifecycle
Staging uses synthetic or explicitly approved data. Customer information is not casually copied to Skilak’s environment. Final network and identity integration happens at the customer site.
Define users, workflows, data sensitivity, model needs, identity, network boundaries, facilities, and acceptance criteria.
Deliverable · Solution brief and responsibility mapAssemble and configure the appliance on Skilak’s controlled staging network using synthetic or customer-approved test data.
Deliverable · Configured build and deployment recordLoad-test the target workflows, exercise retrieval, verify restore procedures, and inspect network behavior before shipment.
Deliverable · Pre-install validation resultsMove the system under an agreed chain of custody, then rack or place it in the customer’s controlled server room or secure IT space.
Deliverable · Custody and installation recordJoin the approved local network, configure private DNS and HTTPS, integrate identity, and apply the customer-approved firewall policy.
Deliverable · Operational private serviceRun the agreed tests with customer stakeholders, document results, train operators, and hand over support and recovery runbooks.
Deliverable · Signed acceptance packageControl domains
Controls are selected to fit the customer’s system boundary, policy, risk decisions, and evidence requirements.
Network
The user interface is published only to approved internal segments. Model and retrieval services stay on restricted backend networks and are not exposed directly to the internet.
Remote access
Remote employees reach SkilakSpool through customer-managed VPN or zero-trust network access. Skilak does not create an unmanaged back door around existing controls.
Identity
Deployments can use local accounts or approved enterprise identity. Administrative access is separated from ordinary use and aligned to least privilege.
Egress
The target state is no public AI or customer-data egress. If cloud identity, updates, or support require connectivity, each destination is documented and explicitly approved.
Data
Source documents, indexes, conversations, logs, backups, and retention rules remain governed inside the customer environment.
Operations
Configuration, recovery, patching, and escalation procedures are documented during handoff so ownership is clear after go-live.
Acceptance evidence
Exact acceptance criteria are agreed during discovery. The following evidence patterns keep results concrete and reviewable.
| Test | Expected outcome | Evidence |
|---|---|---|
| Disconnected rehearsal | The approved AI workflow remains available without a public internet path. | Packet capture, firewall review, and a documented destination inventory |
| Grounded retrieval | Answers based on approved documents return traceable source citations. | Representative question set with reviewer-checked citations |
| Recovery | The service and approved knowledge base can be restored from the defined backup set. | Destroy, restore, and re-query exercise with timestamps and results |
| Model quality | The selected model produces coherent, useful output for the agreed priority workflows. | Customer-approved evaluation set and acceptance record |
Responsibility map
A responsibility matrix is finalized for each engagement so operations do not depend on assumptions.
Skilak
Customer
Shared
Map the system
A discovery briefing produces a physical, logical, and responsibility view your business, IT, and security stakeholders can review together.