| Public cloud | Account, network, identity, logs, approvals | Platform rollout, gateway, model runtime, evidence | Approved cloud account, private network path, identity owner | Fast pilot with enterprise governance |
|---|
| Private cloud | Private regions, storage, security tooling, retention | Deployment workflow, routing, observe/monitor setup | Compute capacity, image/artifact path, logging target | Data residency and internal platform standards |
|---|
| On-premise | Datacenter, hardware, network, identity, operations | Platform packaging, launch path, readiness reporting | Runtime nodes, storage, ingress path, admin access model | Low-egress or owned-infrastructure AI workloads |
|---|
| Restricted network | Connectivity rules, change windows, evidence retention | Private gateway pattern and operating controls | Approved package path, local registry/cache, review owners | Sensitive workloads with constrained outbound access |
|---|
| Air-gapped | Offline environment, transfer process, local evidence store | Offline deployment package and validation checklist | Disconnected install path, model artifact transfer approval | Disconnected environments where external dependency is not acceptable |
|---|