Outpost vs SaaS: Choosing the Right Arbitex Deployment Mode
Not every organization can send AI traffic through a cloud service — and not every organization needs to run infrastructure on-premises. Arbitex Gateway ships with two deployment modes designed for these different realities: Cloud SaaS through the Arbitex-hosted control plane, and Hybrid Outpost where the data plane runs inside your network. Some organizations use one. Some use both.
Choosing the right deployment mode depends on your data residency requirements, compliance posture, infrastructure capacity, and how your teams actually use AI models. This guide breaks down when each mode fits and how they work together.
When to Choose Cloud SaaS
Cloud SaaS is the fastest path to AI governance. There is no infrastructure to provision, no containers to manage, and no GPU capacity to plan for. You connect your identity provider, configure DLP policies, and AI traffic begins flowing through the governance layer.
Time to deploy is measured in hours, not weeks. SAML SSO integration, DLP policy configuration, and provider routing setup can all be completed in a single onboarding session. Updates ship automatically — new DLP recognizers, policy engine capabilities, and platform features are available without any action from your operations team.
Multi-region availability means traffic is processed close to your users. The SaaS platform handles scaling, redundancy, and failover without operational burden on your team.
Cloud SaaS is the right choice for organizations where AI governance is the priority and cloud-hosted processing of AI traffic metadata is acceptable under your compliance framework. Most commercial enterprises, SaaS companies, and organizations without air-gap requirements start here.
When to Choose Outpost
Outpost exists for organizations where AI traffic — including prompt content and model responses — cannot leave the network boundary. This is not a preference. For many regulated and classified environments, it is a hard requirement.
Data residency is the primary driver. When regulations, contracts, or security classifications require that prompt content never transits third-party infrastructure, Outpost puts the entire DLP pipeline, policy engine, and audit subsystem inside your authorization boundary. No prompt text, no response content, and no detected entity data ever leaves your network.
Air-gap deployments are fully supported. For defense contractors operating under ITAR/EAR, government agencies with CUI handling requirements, and research institutions with pre-publication IP restrictions, Outpost runs with zero external connectivity. Configuration updates are applied through offline transfer mechanisms.
On-premises AI models pair naturally with Outpost. Organizations running local Ollama instances, private model endpoints, or custom fine-tuned models behind their firewall can route all AI traffic through Outpost governance without any data leaving the premises at any point in the request lifecycle.
Outpost requires infrastructure capacity — container runtime, CPU allocation, and optionally GPU resources for model inference. Organizations choosing Outpost are trading operational simplicity for complete data sovereignty.
The Hybrid Option
Many organizations have both requirements: regulated data that must stay on-premises and general-purpose AI usage that benefits from cloud convenience. Hybrid deployment addresses this by running Outpost for sensitive workloads and Cloud SaaS for everything else.
A defense contractor might route ITAR-controlled technical discussions through an air-gapped Outpost instance while allowing corporate functions — HR, marketing, general business operations — to use Cloud SaaS with standard DLP policies. A healthcare system might keep clinical AI interactions on-premises via Outpost while routing administrative and operational AI usage through the cloud portal.
Both deployment modes share the same policy language, the same DLP pipeline architecture, and the same audit log format. Policies authored in the cloud portal can be exported and applied to Outpost instances. Audit logs from Outpost can be aggregated with cloud logs for unified compliance reporting — or kept entirely isolated, depending on the classification requirements.
Technical Comparison
| Capability | Cloud SaaS | Hybrid Outpost |
|---|---|---|
| Deployment | Managed cloud service | Customer-hosted containers |
| Data residency | Cloud-processed | Fully on-premises |
| Update cadence | Automatic, continuous | Manual apply via config export |
| Infrastructure required | None | Container runtime + compute |
| CPU trial mode | N/A | Supported — no GPU required |
| GPU production mode | Managed by Arbitex | Customer-provisioned GPU |
| Configuration backup | Managed | Customer-managed export/import |
| Multi-tenant | Built-in org isolation | Single-tenant by design |
| Model inference | Cloud GPU fleet | Local GPU or CPU fallback |
| Audit log destination | Cloud portal + SIEM export | Local storage + optional SIEM |
CPU Trial Mode
Outpost supports a CPU-only trial mode that runs the full governance pipeline — including contextual validation — without GPU hardware. Inference latency is higher on CPU, but the full 3-tier DLP pipeline, policy engine, and audit system are fully functional. This allows organizations to evaluate Outpost capabilities, validate policy configurations, and run pilot deployments before committing to GPU infrastructure for production throughput.
Getting Started
Cloud SaaS: Talk to the Arbitex team to create your organization, connect your identity provider, and begin configuring DLP policies. The platform overview covers the full capability set.
Outpost: Contact the Arbitex team to receive the Outpost deployment package. The get started guide walks through initial setup, and the integrations page covers provider configuration for both cloud and on-premises AI models.
Hybrid: Start with Cloud SaaS for immediate coverage, then add Outpost instances for workloads that require on-premises governance. Both modes use the same policy language — policies created in the cloud portal export directly to Outpost configuration.
Request a demo to see both deployment modes in action, or explore the platform to understand the full governance pipeline that runs identically in both environments.