FAQ

Everything you need to know before getting started

Clear answers to the questions organisations ask most about private AI — covering pricing, security, data residency, governance, integrations, deployment and support. Whether you’re a startup, an SME, an enterprise or a government team, if your question isn’t answered here you can ask it directly on a free discovery call.

Getting Started

Start with a free AI Discovery call — a 30-minute conversation about what you’re trying to solve. No preparation is required and there’s no hard sell. From there, most organisations move to a fixed-price AI Readiness Workshop that produces a practical roadmap and a recommended first use case, then to a scoped Private AI Deployment. You can book a discovery call at sovata.ai/book.

A private AI instance is an AI system deployed inside infrastructure you control — your own servers or cloud tenancy — rather than a shared public platform. Your data is processed there under your governance rules instead of being sent to an external vendor, and you control the model version, access rules and update schedule. It doesn’t mean building a model from scratch: it uses a strong existing model wrapped around your own knowledge.

No. You don’t need any internal AI engineering capability. Sovata brings the technical depth — we design, build and operate the system for you — while you bring the knowledge and context about your business. This is exactly who we work with: organisations that want the benefits of private AI without hiring a specialist team to run it.

The free AI Discovery call exists precisely to answer that honestly. We’ll explore your business problem, likely use cases and data requirements, then give you a straight assessment of whether private AI is the right fit. If it isn’t — or if a simpler tool would serve you better — we’ll tell you on that first call rather than sell you something you don’t need.

Pricing & Costs

There’s no flat price because the cost drivers genuinely vary. Instead, pricing is staged: AI Discovery is free, the AI Readiness Workshop is a fixed fee quoted upfront, and a full Private AI Deployment is scoped per organisation after that workshop. You receive a genuine range and the specific factors that move it before committing to anything.

No. A private AI deployment behaves like a project-based technology implementation, not a per-seat monthly subscription. You invest upfront to design and build the system, and running costs are typically fixed and predictable once it’s live — rather than scaling unpredictably with usage the way metered cloud AI tools do.

Six main factors: your data volume and quality; governance complexity; infrastructure choice (using existing infrastructure is cheaper than building new); the number of use cases; integration requirements such as CRM, document management or ticketing; and ongoing operation for monitoring and governance. We break these down transparently so you can see exactly what’s driving your quote.

It depends on your scale and sensitivity. A private deployment usually costs more upfront, but running costs are typically fixed and predictable once built — which often works out better at scale. For a small team with light usage, a public tool like ChatGPT Enterprise can genuinely be more cost-effective, and we’ll tell you so honestly rather than over-sell.

Small Business & SMEs

No. Sovata AI works with organisations of all sizes — startups, small businesses, medium-sized businesses, enterprises and government. You don’t need a large IT department or an enterprise budget to benefit. Every solution is tailored to your goals, infrastructure, security needs and budget, and many clients begin with a small pilot project and scale over time.

Often, yes — especially by starting small. Because deployments are scoped to your budget and can begin with a single, focused use case, you don’t need enterprise-scale spend to get value. The economics work best where there’s real usage volume or genuinely sensitive data; if a simpler, cheaper option fits your situation better, we’ll say so.

Yes, and many clients do exactly that. A common path is a small pilot — often a staff knowledge assistant using internal-only data, which is low-risk and delivers value quickly. Once it’s proven, the same governed instance can extend to more use cases and teams over time, so you scale on evidence rather than committing everything upfront.

Absolutely — that’s exactly who we work with. You don’t need technical staff or AI expertise in-house. You bring knowledge of your business and your customers; we bring the technical depth and operate the system for you. Sovata designs, builds and runs the deployment so you can focus on using it, not maintaining it.

Enterprise AI

Yes. A private AI instance can scale from a single pilot to multiple use cases and teams across a large organisation, all inside infrastructure you control. Because governance boundaries and access rules are defined per team and use case, you can extend the system incrementally while keeping data access tightly controlled at every step.

Yes. A private AI instance can be deployed inside your own cloud tenancy — for example your own Microsoft Azure environment — or your own data centre. Your data is processed inside that environment rather than sent to an external provider, so it stays within your security perimeter, your identity controls and your existing infrastructure governance.

Because the architecture is designed for it. Deployments run inside infrastructure you control, data doesn’t leave your environment, and governance boundaries are agreed before any build. We work within your existing security and compliance framework rather than asking you to adopt ours, and we’re happy to engage directly with your security, procurement and vendor-risk teams during scoping.

Security & Privacy

Inside infrastructure you control — your own servers or your own cloud tenancy. Your data is processed there rather than sent to an external provider, so it stays within your security perimeter. Data residency is agreed before any build begins, so if your data must remain in a specific country or region, that requirement is designed in from day one.

No — that’s the core of the private AI model. Your data is processed inside the infrastructure you govern rather than sent to a shared external platform. Whether the instance can reach any external tool or the internet is a governance decision you make, not an architectural default, so you decide exactly what the system can and can’t connect to.

It removes one major risk — your data leaving your infrastructure — but security still depends on how the system is configured, monitored and governed. A private instance gives you the control needed to be genuinely secure, but that control has to be used well. That’s why we design governance boundaries up front and keep monitoring the system after go-live.

Yes, where that’s a requirement. Data residency is one of the first things agreed during the “set the boundaries” step, before any technical build begins. If keeping data within a specific country — such as New Zealand — is a requirement, it’s designed in from day one rather than retrofitted later. Sovata is headquartered in New Zealand and supports local residency directly.

AI Governance

Governed AI means there are explicit, agreed rules for what the AI can access, what it must escalate to a human, and what it should never do. These boundaries are defined with your team before deployment and monitored on an ongoing basis after go-live. Governance is designed in from the start, not bolted on afterwards — it’s what makes AI safe to use with sensitive work.

You do. The rules for what data the AI can access, what it should escalate, and what it must never do are agreed with your team during scoping, based on your policies and risk appetite. Sovata brings the expertise to help you set sensible boundaries, but the decisions — and the accountability — remain with your organisation.

Yes. For any workflow that carries real consequence — such as case, compliance or service decisions — a human makes the decision, with the AI providing triage, summaries or draft responses. Escalation points are defined up front as part of governance, so the system knows when to hand off to a person rather than acting alone.

Through a combination of grounding, boundaries and monitoring. The AI answers from your validated knowledge base rather than guessing, governance rules limit what it can access and do, and consequential decisions are escalated to a human. After go-live we keep monitoring performance and refining the system, because governance is an ongoing practice rather than a one-time setup.

Technology & Integrations

A private AI instance can connect to the systems you already run — SharePoint, document management systems, CRMs, ticketing tools and other internal data sources — with access controlled entirely by you. We map exactly which integrations you need during the AI Readiness Workshop, so the system works within your existing workflows rather than forcing you to change how you operate.

Yes. A private AI instance can be deployed inside your own Microsoft Azure tenancy and connected to Microsoft 365 tools such as SharePoint, with access governed by your existing identity and permission controls. Deploying inside your Azure environment keeps data within your security perimeter while letting the AI work with the content your team already uses.

We don’t build models from scratch. A deployment uses a strong existing open-weight or licensable model, with your own knowledge — policies, procedures and documents — structured around it. The architecture is model-agnostic, so we choose the right model for your needs and can change it over time without rebuilding your whole system.

Because the architecture is model-agnostic, your system isn’t tied to any single model’s lifecycle. If a model is deprecated or a better one becomes available, it can be swapped without rebuilding your knowledge base or workflows. You control the update schedule, so provider changes don’t silently break your automations the way they can with shared public tools.

Deployment

Most organisations go from workshop to a working system in 6–12 weeks. The exact timeline depends on the complexity of your use case, your data and your governance requirements. We give you an honest estimate once we understand your situation, and many clients start with a focused pilot that delivers value quickly before scaling further.

Four steps. First, define the problem — the work where private AI adds most value with least risk. Second, set the boundaries — data rules, access controls and escalation points, agreed before any build. Third, prepare the knowledge — structure, test and validate the content the AI will use. Fourth, deploy and operate — launch, onboard your team, and keep monitoring and governing the system.

Wherever you control it. A private AI instance can run inside your own cloud tenancy, on your own servers, or in a hybrid arrangement — whatever matches your infrastructure, security requirements and data-residency rules. The defining feature isn’t cloud versus on-premise; it’s that the environment is one you govern, so your data stays under your control.

A production system, not a proof of concept. Sovata designs, deploys and operates a working system inside your infrastructure, then stays on to monitor, govern and improve it. The goal is a governed tool your team relies on day to day — not a demo that’s shipped and forgotten.

Support & Training

Yes. There’s no handoff at go-live. Sovata stays on to monitor performance, keep governance current and improve the system as your needs change. A private AI deployment is operated, not shipped and forgotten — ongoing operation is a core part of the engagement rather than an optional add-on.

Yes. Onboarding your team is part of deployment. We help your people understand how to use the system effectively and how its governance boundaries work, so adoption is confident and safe. Because the system is built around your own knowledge and workflows, it’s designed to feel intuitive to the people who’ll use it every day.

We handle it. Because Sovata operates the system after go-live, we monitor for issues, maintain the underlying infrastructure and models, and adjust the system as your needs or data change. If you need new use cases, integrations or governance updates, the same team that built the system extends it — there’s no need to start over.

Industries

Sovata AI works across professional services, public sector and government, healthcare, education, financial services and other regulated or knowledge-heavy industries. The approach suits any organisation that handles sensitive information or relies on internal expertise and needs to keep that data under its own control. Every deployment is tailored to the rules and context of your specific sector.

Yes. Public sector organisations are a core focus, precisely because data sovereignty, governance and accountability matter most where public trust is involved. A private AI instance keeps data inside infrastructure you control and enforces explicit governance boundaries — which aligns well with public-sector expectations around residency, transparency and human accountability.

Yes. Regulated industries are where private AI’s control and governance matter most. Because data stays inside infrastructure you govern, boundaries are agreed up front, and humans own consequential decisions, the approach fits sensitive workflows in areas like healthcare, financial services and compliance. We work within your existing regulatory framework rather than asking you to adopt a new one.

Compliance

Yes. Data residency is agreed during the “set the boundaries” step, before any technical build. If your data must remain in a specific country or region, that’s designed into the architecture from day one. Because the system runs inside infrastructure you control, sovereignty and residency requirements are addressed structurally rather than promised contractually.

Yes — a private AI deployment is designed to support your obligations under regulations such as GDPR or the Privacy Act. Because your data is processed inside infrastructure you control, with governance boundaries agreed up front, the architecture is built around the residency and privacy rules that apply to you. We design to support your obligations rather than claiming certifications we don’t hold.

Boundaries are defined per engagement based on your regulatory context, existing infrastructure and internal policies. Rather than asking you to adopt a new framework, we work within your organisation’s existing security and compliance requirements. We’re transparent about what the architecture does and doesn’t do, and we never claim a certification or compliance status Sovata doesn’t hold.

About Sovata AI

Sovata is a private AI company headquartered in Auckland, New Zealand, supporting organisations worldwide. We design, deploy and operate secure AI inside your own infrastructure, so your data never leaves your control. Our tagline sums up the model: your AI, your environment, your control — governed AI built around your knowledge and owned by you.

It’s a fair question, and the honest answer is the people. Sovata is new; the experience behind it isn’t. Our team brings a decade at IBM in responsible AI, 16 years in banking and data governance, and hands-on experience deploying governed AI for healthcare. You meet the whole team before committing to anything, and we’re upfront about what we can and can’t do.

Sovata is headquartered in Auckland, New Zealand, and supports organisations worldwide. Being New Zealand–based means we can guarantee local data residency where it’s required, and it shapes our focus on sovereignty, governance and trust. You can reach us at hello@sovata.ai or book a free discovery call at sovata.ai/book.

Sovata is a small, senior, Auckland-based team, with no handoff between discovery and delivery. Alan Kan (CEO) is a responsible-AI pioneer with a decade at IBM. Tracey Savelio (Head of PR) brings 16 years at Kiwibank and sits on the AI Forum NZ Pacific Advisory Panel. Ariena Phannaen (Head of AI Delivery & Design) has deployed governed AI for healthcare triage platforms.

Ready to talk it through?

Book a free discovery call. No preparation required — just tell us what you’re trying to solve.