Ithaca Cloud for secure & regulated teams

Private AI your security team will actually approve.

Deploy approved open-source AI software inside infrastructure you can govern, audit, and prove. Every workspace is isolated, your data isn’t trained on or retained, and you bring the models and keys. AI without losing control of your data.

Book a security reviewSee the catalog →

What’s true today

The controls already baked into every workspace.

Workspace isolation

Every app runs in its own container — separate data, endpoints, memory, and spend. Nothing bleeds between clients, projects, or people.

No training, no retention

Your prompts and data aren’t used to train models or retained beyond your workspace.

Bring your own models & keys

Point a workspace at your own endpoint (OpenAI, OpenRouter, vLLM, Ollama). The inference path is one you control.

Open-source, auditable, portable

The apps you run are open source — you can inspect them and export your data. No black box, no lock-in.

Hard spend cap + metering

Per-second billing, idle auto-suspend, and a cap you set. Costs stay predictable and attributable.

Tenant-scoped access

Workspaces, members, and billing are scoped to your organization.

Available on request

Scoped with your team as part of an enterprise agreement.

Dedicated GPUs

Private GPU hosting, including RTX 5090, provisioned for your workloads.

DPA & BAA

A Data Processing Agreement, and a HIPAA Business Associate Agreement where applicable.

Custom deployment

Single-tenant or self-managed deployment topologies, scoped with your team.

Security review & MNDA

A mutual NDA and a walkthrough of the architecture and data flows for your security team.

On the roadmap

Committed, not yet shipped — we’ll tell you exactly where each one stands.

SSO / SAML & SCIM

Single sign-on and automated user provisioning.

RBAC

Role-based access control across workspaces and admin functions.

Audit logs

Exportable activity logs for usage, access, and admin actions.

Backups & snapshots

Scheduled backups and point-in-time workspace snapshots.

Data retention controls

Configurable retention and deletion policies per workspace.

SOC 2

Formal SOC 2 program — we won’t claim a certification before we hold it.

Straight talk: we won’t claim a certification or control we don’t have. If a requirement isn’t live yet, we’ll show you where it sits on the roadmap and put real dates against it. That’s the whole point of a platform you can audit.

Let’s scope it

AI without losing control of your data.

Tell us what your security team needs — SSO, a BAA, dedicated GPUs, a self-managed deployment — and we’ll come back with a plan.