What "on-prem" actually means here
Most "private AI" offerings still call out to a vendor's cloud for inference, telemetry, or model updates. On-premises deployment in a regulated pharma setting means something stricter: the model weights, the runtime, and the inference all live on hardware the company controls, inside a network boundary the company defines. No prompt, no completion, and no metadata leaves that boundary.
Hyfstele runs open-weight models — models whose parameters are published and downloadable — rather than a closed API you can only reach over the wire. That choice is what makes the rest of the posture possible: you can only prove what a model is if you can hold the weights in your own hands.
The four controls, each verifiable on your hardware
Hyfstele's posture rests on four independent controls. None of them depends on trusting Hibiscus. Each produces evidence a pharma quality or security team can check for itself.
Weight provenance
The weights running on your hardware are hashed and proven byte-identical to the public artifact. What you audited is what you are running — not a re-quantized or silently modified copy.
Latent capacity enumerated
Dormant and latent capacity in the model is enumerated so the surface you are accepting is written down, not assumed. You see what the model can do, stated plainly.
No egress
There is no route to the internet and no external name to resolve. Things go in, nothing comes out. Data residency holds by construction because the data physically cannot leave.
Signed audit chain
Every inference call is anchored to a tamper-evident audit chain, signed with post-quantum cryptography (ML-DSA). You can reconstruct exactly what was asked and answered, and prove the record was not altered.
Weight provenance: proving byte-identity on your own metal
The claim "this is the open-weight model you evaluated" is only worth anything if it can be checked after deployment. When the model is installed on the customer's hardware, its weight files are hashed and compared against the hash of the public artifact from the model's original distribution. If a single byte differed — a swapped tensor, an injected adapter, a repacked checkpoint — the hashes would not match.
This is deliberately narrow. Byte-identity proves the artifact is the one you assessed. It does not prove the artifact is free of hidden behavior. Those are different questions, and conflating them is exactly the overclaim we refuse to make.
No egress: the "nothing comes out" posture
Data residency and confidentiality obligations are usually enforced with policy: network rules, DLP scanning, promises. The no-egress posture enforces them physically. The deployment has no route to the public internet and no external name to resolve, so there is no path for prompts, completions, embeddings, or telemetry to reach an outside party.
For a pharma team, this collapses a long list of downstream risks into a single verifiable fact. There is no vendor endpoint receiving your promotional material, your clinical language, or your regulatory correspondence — because there is no reachable vendor endpoint at all. You can verify it the way you would verify any air gap: inspect the interfaces and the routing.
The signed, tamper-evident audit chain
GxP and 21 CFR Part 11 both turn on the same idea: if you cannot reconstruct who did what, when, and prove the record was not altered, the record does not count. Hyfstele anchors every inference call — the input, the model response, the context — to an append-only audit chain. Each entry is signed with post-quantum cryptography (ML-DSA), so the chain is tamper-evident: any change to a past record breaks the signatures that follow it.
The practical effect is that "the AI helped with this review" stops being a soft assertion and becomes a verifiable, court-durable record. An auditor does not have to trust your logging pipeline; they can check the signatures.
How this maps to GxP, data residency, and 21 CFR Part 11
The controls are not compliance theater bolted on afterward — each one answers a specific obligation.
| Obligation | Which control answers it |
|---|---|
| 21 CFR Part 11 — audit trail & record integrity | Signed, tamper-evident audit chain (ML-DSA) captures every inference call and proves records were not altered. |
| 21 CFR Part 11 — system validation | Byte-identical weight provenance fixes exactly what is running, so the validated state is the running state. |
| GxP — controlled, documented systems | Enumerated latent capacity documents the accepted surface; provenance and audit chain document behavior over time. |
| Data residency / confidentiality | No egress means regulated data physically cannot leave the perimeter — residency by construction, not by policy. |
| Model provenance / supply-chain assurance | Byte-identity to the public artifact establishes a checkable chain of custody for the weights. |
These controls support your compliance program; they do not by themselves constitute regulatory approval. Validation and qualification remain your quality organization's responsibility.
The honest posture. We do not scan the model, and we do not claim the model is clean, safe, or free of hidden behavior. No one can honestly promise that about a large open-weight model. What we do is make four controls verifiable on your own hardware: byte-identical weights, enumerated latent capacity, no egress, and a signed audit chain. You get evidence you can check yourself — not our word.
Where this shows up: MLR promotional review
The first production use case is an AI assist for pharmaceutical MLR (Medical, Legal, Regulatory) promotional review. A live demo runs at mlr.hyfstele.com.
The doctrine is deliberately conservative: "It flags. You decide." The flow is Flag → Judge → Prove, and there is no LLM inside the flag decision plane. The model surfaces candidate issues for a human reviewer; the decision, and accountability for it, stays with the reviewer. Every step lands in the signed audit chain, so the review is reconstructable end to end.
Frequently asked questions
What is an on-premises LLM for a pharmaceutical company?
It is an open-weight language model that runs entirely inside the pharma company's own perimeter — on its own hardware, air-gapped, with no route to the internet. Prompts and completions never leave the boundary. Hyfstele deploys such models with four controls the company can verify on that hardware: byte-identical weight provenance, enumerated latent capacity, no egress, and a post-quantum-signed audit chain.
Does Hyfstele guarantee the model is safe or backdoor-free?
No. We do not scan the model and we make no claim that the model is clean, safe, or free of hidden behavior — that is not something anyone can honestly promise about a large open-weight model. Our posture is different: we make four controls verifiable on your own hardware and hand you the evidence. You check it; you don't take our word for it.
How does an on-prem LLM satisfy 21 CFR Part 11?
Part 11 turns on record integrity and audit trails. Every inference call is anchored to a tamper-evident audit chain signed with post-quantum cryptography (ML-DSA), so who-asked-what-and-when is reconstructable and any later change to a record is detectable. Byte-identical weight provenance also fixes what is running, so your validated state matches your running state. These controls support a Part 11 program; validation remains your quality organization's responsibility.
How is data residency handled if there is no internet connection?
By construction. The deployment has no route to the internet and no external name to resolve, so regulated data has no path out of the perimeter — things go in, nothing comes out. Residency is enforced physically rather than by policy, and you can verify it by inspecting the interfaces and routing on your own hardware.
What does "proven byte-identical to the public artifact" mean?
The weight files running on your hardware are hashed and compared to the hash of the model's original public distribution. A match proves the running model is exactly the artifact you evaluated — not a modified, re-quantized, or adapter-injected copy. It establishes chain of custody for the weights. It does not, on its own, prove the artifact is free of hidden behavior; that is a separate question we do not overclaim on.
See it running inside a perimeter
Hyfstele is built by Hibiscus Consulting LLC (Raleigh/Cary, NC; SBIR-eligible small business). See the MLR promotional-review assist live, or talk through an on-prem deployment for your environment.
View the MLR demo Email blake@hibiscus.buzz