Learn / Security and privacy

What is private or air-gapped RAG?

Updated 3 October 2026 · 2 min read

Short answer

Private RAG keeps your documents, vectors and models inside infrastructure you control, and air-gapped RAG goes further by running with no connection to the outside network. They are chosen when regulation, contracts or risk make sending data to a third party unacceptable.

With troveGEN

troveGEN runs anywhere on the control spectrum: managed with isolation, your own vector database and models, or fully air-gapped with local embeddings, reranking and language model.

See what troveGEN provides ↓

Levels of control

  • Managed with isolation: a provider hosts everything, with your data separated from other customers.
  • Bring your own vector database: the index lives in your account, while the pipeline is a service.
  • Bring your own models: embeddings, reranking and answers come from endpoints you control.
  • Self-hosted: the whole stack runs in your cloud account or data centre.
  • Air-gapped: the same stack with no outbound network at all.

What an air-gapped stack needs

Every external call has to have a local equivalent: an embedding model, a reranker, a language model for answers, OCR with its language data, and a way to bring in documents from internal systems without the internet. Updates and model weights arrive by controlled transfer.

Trade-offs

You take on operations: capacity, patching, monitoring and model upgrades. Local models are usually smaller than the largest hosted ones, which can lower answer quality, though retrieval quality depends mostly on the pipeline. Many organisations choose a middle path, such as their own vector database with a trusted model provider.

Questions to ask a vendor

  • Where are vectors and text stored, and who can read them?
  • Can every model be replaced with one I host?
  • What leaves my network, and when?
  • How is a deleted document removed from every copy?
  • Which features are unavailable in the offline mode?

Key takeaways

  • Sovereignty is a spectrum from isolated hosting to fully offline.
  • Air-gapped needs a local replacement for every external call.
  • You trade operational effort for control.

How troveGEN helps with private and air-gapped RAG

troveGEN offers the whole spectrum: managed with per-customer isolation, your own vector database, your own models and keys, and a supported fully air-gapped mode with local embeddings, a local reranker and a local language model. Nothing an offline deployment needs is paywalled, and credentials are encrypted and never returned.

What troveGEN provides

  • Bring your own vector database, embedding model, reranker and language model
  • A supported fully offline mode with a local stack
  • No feature an offline deployment needs is paywalled
  • Your own keys, encrypted at rest
  • The same API and console in every mode

See the options Start free — 500 pages

Frequently asked questions

Is air-gapped RAG slower?

Not inherently. Speed depends on your hardware and models. Local inference needs enough compute for the models you choose.

Can I start managed and move later?

Yes. The API is the same, but moving the index means re-ingesting into the new target.

Does it support scanned documents offline?

It can, with a local OCR engine and its language data installed.

How does troveGEN help with private and air-gapped RAG?

troveGEN runs anywhere on the control spectrum: managed with isolation, your own vector database and models, or fully air-gapped with local embeddings, reranking and language model. It provides: Bring your own vector database, embedding model, reranker and language model; A supported fully offline mode with a local stack; No feature an offline deployment needs is paywalled; Your own keys, encrypted at rest; The same API and console in every mode.

Keep reading