Three deployment modes: on-prem, hybrid, multi-cloud
Agent-User Runtime runs locally by default and can be upgraded to a fully private deployment or hybrid cloud. The model layer simultaneously integrates external public model APIs, private local models, enterprise cloud LLMs, and custom LLMs — all under unified governance and context policy.
Three deployment modes
From pure on-prem to full privatization — covers every compliance and business need.
Pure on-prem
Desktop Runtime can run offline; models can be invoked privately on local infrastructure; external network calls can be disabled by configuration.
- Works in disconnected environments for high-sensitivity assessment
- Models deployed on intranet / mainstream GPU clusters
- Configurable data-residency policy to avoid default uploads
- Supports SM cryptography and local KMS custody
Hybrid cloud
Desktop Runtime + enterprise cloud control plane; smart routing between local and external models.
- Local Runtime handles core tasks
- Cloud control plane syncs policy and audit
- External model APIs optional for non-sensitive tasks
- Unified SSO + unified audit logs
Multi-cloud federation
Federated governance across multiple cloud providers and LLM vendors; auto-routing by data sensitivity.
- Public cloud / private cloud / private IDC hybrid access
- Provider adapters (Qwen / DeepSeek / Doubao / OpenAI-compatible)
- HITL approval queue + budget gates
- Data classification auto-selects model and storage location
Deployment architecture
Six layers from client to model to enterprise integration — fully observable and governable.
Electron Desktop / Browser
Node.js · five-layer security bridge
Unified routing · context policy · redaction
Qwen · DeepSeek · Doubao · external vendor APIs · Private LLM
SSO · KMS · audit delivery
Classified protection · cryptography capability · key custody
Traffic enters the Runtime from the client and is routed through the LLM Gateway to the model matrix, governed end to end by SSO, KMS, and audit controls.
Model integration matrix
Single Runtime entry, policy-based routing to different model layers.
| Model | Type | Use case |
|---|---|---|
External vendor LLM APIs | External public model API | General Q&A, document processing, code generation |
On-prem private model | On-prem deployment | High-sensitivity data, classified industries, SOEs |
Enterprise cloud LLM | Enterprise-dedicated cloud model | Medium-sensitivity scenarios, cross-region teams |
Custom / industry vertical LLM | Self-developed or custom model | Industry know-how, finance / legal / manufacturing |
Enterprise integration
Can connect with existing identity, key-management, and audit systems.
SSO single sign-on
Supports OIDC / SAML 2.0, integrates with AD / LDAP / Feishu / DingTalk / WeCom / Okta / Azure AD.
KMS key custody
Model credentials and knowledge-base encryption keys go through enterprise KMS (AWS KMS / Aliyun KMS / HashiCorp Vault / SM HSM); no plaintext locally.
Audit log shipping
JSONL audit events shipped in real time to SYSLOG / Kafka / SIEM (Splunk / Aliyun SLS / Tencent CLS), with SM signature support.
LDAP / OU sync
Org structure auto-synced to Agent-User's multi-tier permission matrix (enterprise / department / business line / role).
Security & compliance
Designed for ToB / ToG high-compliance scenarios.
- Designed for MLPS 3.0 technical assessment
- Can align with ISO 27001 information-security management requirements
- Can connect SM2 / SM3 / SM4 capabilities by project need
- Configurable data-residency and zero-trust access policies
- Supports audit signing and traceability design
- Supports tenant isolation and end-to-end encryption design
Get the deployment white paper / apply for POC
We provide end-to-end services from requirements analysis, solution design, POC validation to go-live and O&M.