All insights

Air-Gapped & On-Prem

Hybrid Deployment: Where to Draw the Line

· 10 minute read

Hybrid is not a compromise slogan. It is a list of hops you can defend. Draw the line on data classes and duties, not on whoever shouted 'cloud first' last.

Hybrid is the word committees use when they cannot choose. The vendor hears it as permission to put the control plane wherever their product already lives. The CISO hears it as a temporary sin. The secretary hears it as progress. None of those hearings is a design.

A defensible hybrid is a line. On one side, classes that do not leave: live personal data, embeddings of that data, tool results, traces, keys. On the other, classes that may leave under a written reason: public circulars, synthetic eval, maybe anonymised telemetry that you have actually inspected. Everything else is a hop you have not admitted.

This decision guide is how we force the line onto one page. It is written for CIOs who are being asked to sign a 'phased cloud' story. Phases that never name the hop are not phases. They are a direction of travel with no brake.

Lines that hold

Draw lines on classes and duties, not on brands. 'Inference in Mumbai region' is not a line. 'Prompts never leave the SDC VLAN; model weights may be fetched from a connected build room' is a line. The first sentence names a vendor's map. The second names your duty.

If a row is blank in your note, the vendor will fill it.
Class / dutyUsually keep insideMay sit outside if
Live personal data and case filesYesNever, unless a statute and counsel say so
Embeddings / chunks of the aboveYesSame as the source text
Prompts and retrieved contextYesOnly if redaction is proven and accepted
Traces, screenshots, eval gold itemsYesSynthetic only on the outside
Public circulars and gazettesOptionalThey are already public; still watch annotations
Model weights (base, no finetune)PreferredFetched into a build room, then imported
Licence / feature flagsPreferred offlineA fail-open local cache, never a hard runtime dep
Crash telemetryYesNo — this is the usual loophole
Non-personal capacity metricsEitherIf you have seen a sample payload

Five honest hybrids — and two dishonest ones

  • Honest: disconnected run room, connected build room, bag between them. Weights and images travel. Personal data does not.
  • Honest: generation on-prem; a hosted translation or OCR on already-public text only.
  • Honest: primary in SDC, DR in another Indian government hall, with encrypted replication you can name.
  • Honest: officers on a thin client; all stores in the hall; WAN carries pixels and keystrokes, not corpora.
  • Honest: research sandbox on a campus GPU with public models; production agent separate, no shared index.
  • Dishonest: 'documents stay, prompts go' when prompts contain the documents.
  • Dishonest: 'India region' plus a global APM, global safety model, or global support recorder.

The WAN is a hop

District offices talking to an SDC agent over the state WAN is a hybrid whether you like the word or not. Encrypt, identity-bind, and decide what is cached locally. A district laptop that downloads the whole vector index 'for performance' has just created a new store you will not erase.

People are a hop

Support sessions, WhatsApp screenshots, and 'please find attached a sample ticket' are hybrid deployments of the worst kind. If the line says personal data stays, the sample ticket stays. Write that in the support SOP. Architecture cannot survive a helpful forward.

How to draw it in a meeting

  1. List stores, not products: files, chunks, vectors, prompts, traces, eval, adapters, backups, support copies.
  2. Paint each store stay or leave. No 'depends' without a named condition.
  3. For every leave, write the receiver, the country, the retention, and the erasure method.
  4. Kill any leave that exists only for vendor convenience — APM, licence, 'improvement'.
  5. Write the failure mode: if the outside path dies, what still works? If the answer is nothing, you did not hybridise. You outsourced.
  6. Put the painted list in the RFP and the DPA. A line that lives only on a whiteboard will move.

Objections you will hear — and what to do with them

Cloud first is policy.

Cloud-first is a preference for commodity IT, not a waiver of purpose, residency circulars or CERT-In log retention. Ask which policy document forces this hop. If they cannot produce it, it is a mood.

We will tighten later.

Hops grow dependents. A safety queue, a dashboard, a support habit. Tightening later is a migration. If you need time, time-box a synthetic-only outside path and put the end date in the work order.

The model we want only exists hosted.

Then either change the model, change the data you send, or change the claim you make in the RFP. Wanting a model is not a reason to launder a grievance through it.

A ten-day line-drawing playbook

  1. Days 1–2: inventory stores for one workflow, including unofficial copies.
  2. Days 3–4: paint stay / leave with CISO, DPO and the process owner in the same room.
  3. Days 5–6: packet-capture the current pilot. Compare to the paint. The capture wins.
  4. Days 7–8: rewrite the vendor statement of work so each leave is a clause or is deleted.
  5. Days 9–10: file the painted list and the capture summary. Refuse new tools until they get a row.

How this shows up in the file

The note seeking approval should have the painted table on page one. Secretaries can argue about a table. They cannot argue with a paragraph that says 'hybrid approach as discussed'. If you are Prcept or anyone else, you should be willing to implement the table as drawn, including the stays that hurt your preferred SaaS motion.

A one-page line for the secretary

Secretaries do not want a mesh diagram. They want four sentences. What never leaves. What may leave, to whom. What happens if the outside path dies. Who initials a new hop. If you cannot write those sentences without a footnote that says 'except safety processing', you have not drawn a line. You have drawn a maze.

  1. Never leave: live personal data, embeddings of it, traces, keys, tool results.
  2. May leave: public gazettes, synthetic eval, maybe capacity metrics we have inspected.
  3. If the outside dies: inference continues on the last local model; no degraded mode that phones a backup brain.
  4. New hop: CISO + DPO + process owner, or it does not exist.

Put those four sentences above the signature block. Vendors can attach their architecture below. The sentences win on conflict. That is how hybrid stops being a mood.

This article is a field guide, not legal, procurement, electrical or engineering advice. Confirm numbers, duties and designs against the current Gazette, CERT-In directions, your SDC / NIC / campus standards, a site survey and your counsel before you file them.

How to prove this on a rack, not on a slide

“Hybrid Deployment: Where to Draw the Line” only matters if a CISO can fail it. A P1 CIO/CTO should be able to point at a cable, a registry, a licence file, a PDU reading or a SIEM index and say: this is the control. If the only evidence is a brochure that mentions “hybrid AI deployment government”, you do not have the control.

Hybrid is not a compromise slogan. It is a list of hops you can defend. Draw the line on data classes and duties, not on whoever shouted 'cloud first' last. Air-gap and on-prem programmes die in the second month, when the first update, the first crash, or the first GPU lead-time slip arrives. Budget the boring path — media, offline licence, local registry, local traces — in the same note as the model name.

On-prem is not air-gapped. An India region is not either. Write the forbidden path (outbound HTTPS, licence phone-home, crash reporter, hidden model API) as a numbered list and test it with the internet off. Whatever still dies was a dependency you did not draw.

  1. Draw the data path for one user-visible answer under “hybrid AI deployment government”.
  2. Disable outbound internet on staging and run the demo script.
  3. List every remaining hop: update, licence, registry, NTP, DNS, SIEM.
  4. Give each hop an owner inside the department, not only the SI.
  5. Minute the restore or the media-transfer once before go-live.

Close this loop before the next CAB

Put “Hybrid Deployment: Where to Draw the Line” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P1 CIO/CTO, not “the vendor.”

Revisit the item when the model, the GeM term, the region, or the SI changes. “hybrid AI deployment government” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.

Questions this usually raises

Is a hybrid design compatible with DPDP?
It can be, if you know what personal data moves, on what basis, to whom, and how you will erase it. Hybrid is not a lawful basis. It is a topology. Counsel still has to like the hops. This is not legal advice.
Can we keep documents on-prem and send only prompts to a hosted model?
Prompts and retrieved chunks often carry the document. Treat that as a transfer of content unless you have a proven redaction that counsel accepts. 'We only sent the question' is usually false once RAG is involved.
Is MeghRaj 'hybrid' if we also have a departmental rack?
It is two government homes. Still draw the line: which class lives where, how it is copied, who admins each side, what happens when the WAN dies. Two Indian halls do not make a hop automatically harmless.
Where should we draw the line for a first pilot?
Keep personal data, embeddings, traces and tools on-prem or in a hall you already trust. If you must use a hosted model, use synthetic or already-public text and write that limit in the note. Do not pilot on live grievances 'just this once'.

Sources