Try XGEN free for 15 days — nothing to install, runs in your browserStart free trial
PlateerAI Labs

Architecture

Enterprise AI Architecture

Enterprise architecture for AI you can trust

An air-gap and on-premise design that holds data sovereignty, security, and governance — and an Enterprise AI that joins knowledge, reasoning, action, and operations into one system

The foundation architecture behind data sovereignty and the AI runtime

Holding data sovereignty, security, audit traceability, and organizational governance:
an air-gap and on-premise friendly architecture

Connecting knowledge, reasoning, action, and operations into one system:
a reference architecture for the Enterprise AI runtime

/ Design Principles

Architectural design principles

Four design standards every layer shares, so AI can be trusted and operated in an enterprise environment

Grounded answers

Answers rest on the documents, policies, and knowledge models the company holds. When the grounding isn't there, the system says so rather than guessing — which is what keeps hallucination down

Data sovereignty

Runs inside your own infrastructure with no cloud lock-in, including the network-separated environments in finance, public sector, and manufacturing

Composability

Agents, workflows, knowledge, and tools are modules you recombine freely as the work demands

Model neutrality and governance

Choose an LLM by purpose, cost, and accuracy, and keep operations under control through policy, approval, and audit trails

/ Reference Architecture

XGEN 3.0 Enterprise AI architecture

The XGEN 3.0 Enterprise AI layers connecting access, knowledge, reasoning, planning, action, operations, models, and infrastructure

Access channels
Unified Access
Use cases by industry
E-Commerce
Customer chatbot
Public Sector
Citizen support
Finance
Incident prevention
IT Services
Regulation search
Console
User Mode
Developer Mode
Admin Mode
Data sources
Structured Data
Unstructured Data
Enterprise Systems
ERP · CRM · HRM
External Sources
Web · API · 3rd Party
Enterprise AI RuntimeKnowledge · reasoning · planning · action · operations, in one layer
Knowledge
Knowledge Base
Vector DB
Ontology
Document Store
Reasoning
Model Orchestration
RAG Engine
Guardrails
Planning
Harness Runtime
Task Decomposition
Tool Selection
Replanning
Action
Server Tool Runtime
Local Interaction
Approval Gate
Sync Contract
Operations
Monitoring
Logging
Audit Trail

Workflow Orchestration

Agent Execution
Model Routing
Policy Enforcement
Response

Shared Orchestration

Agent Workspace
Session State
Tool Registry
Evaluation & Trace
Platform Services
LLM / ML Settings
On-demand GPU
Vector DB Connection
Data Pipeline
Observability
Security & Compliance
Governance
Model Layer

Public / General LLM

ChatGPTClaudeGemini

Private / Enterprise LLM

XGEN LLMQwendeepseekPolarGemma
Infrastructure

Cloud

AWSMicrosoft AzureGoogle Cloud

On-premise / Private Cloud Air-gap and on-premise friendly

GPU
Container
Database
Storage

/ On-Premise Security

XGEN 3.0 on-premise and security architecture

An external request reaches internal services, AI models, and data only after passing the authentication gateway and trust boundary. Local resources connect only through explicit user approval and least privilege in Xgent Client, with security, audit, and governance applied across server and local execution.

Untrusted (external)Boundary · DMZInternal trust zoneRestricted data zone
UNTRUSTED

User zone

Access from the internal network or over VPN

Web browser

JWT cookie · xgen_access_token

Embedded chatbot

chatbot-embed.js · deployed agent

HTTPS ↓
LOCAL EDGEUser-controlled zone

Xgent local execution boundary

Local resources connect through explicit approval and least privilege

Xgent Client

Secure session with the server-side agent

User approval

Allow, deny, or stop each action

Local Folder · OS

Only selected folders and OS capabilities

Local MCP

Scoped private-network and dedicated tools

Approved Sync Contract ↓
DMZPresentation

Frontend

UI rendering and API rewrites

Next.js Frontend

apps/web

Client AuthGuard

Route guard · first-pass UI gating

API routes / rewrite

Forwarded to the gateway

JWT ↓

Authentication trust boundary

Above this line is spoofable and external; below it is trusted — only the gateway can carry a request across

GATEWAYBoundary

Authentication gateway

Converts a JWT into trusted headers

Rust Gateway

JWT parsing and validation

Cookie → user context

x-user-* header injection

id · roles · permissions · superuser

Spoofing blocked

Clients cannot inject these headers themselves

x-user-* headers ↓
INTERNALInternal trust

Application services

Permission enforcement and access control

xgen-core

ABAC access control

xgen-workflow

Execution · five-stage access control

Dual approval gate

Deployment plus governance approval required

MCP Station

Sandboxed, isolated execution

Internal network call ↓
AIR-GAPPEDInternal · GPU

AI model zone

Every endpoint stays internal

LLM serving

vLLM · SGLang · llama.cpp (in-house GPU)

Embedding and reranker

Sentence Transformers · vLLM

Guard model

Open guard model · fail-closed

Store and retrieve ↓
RESTRICTEDData zone

Data stores

Internal network, restricted access

Qdrant

Vector DB

Application DB

Users, policies, metadata

MinIO

Document object storage

Audit log store

Retention policy applied

Applied at every layer · defense in depth

These controls are not tied to one layer — they operate across the whole request path.

Authentication (AuthN)

  • ·JWT cookie authentication
  • ·Initial SuperUser bootstrap (one time)

Authorization (AuthZ)

  • ·RBAC roles
  • ·Three-layer ABAC permissions (tier, role, permission)
  • ·Least privilege for local folders, OS, and MCP

Data protection

  • ·PII masking
  • ·Guardrails (blocked on failure)
  • ·Blocklists and risk grading

Governance

  • ·Dual deployment and governance approval
  • ·Scheduled reviews (D-5 cadence)
  • ·Risk assessment

Audit and traceability

  • ·Trace plans, tool selection, and file access
  • ·Record server/local results and data exports

Isolation and boundaries

  • ·MCP sandbox execution
  • ·Kill switch for agents, sessions, and local links
  • ·On-premise and air-gap support
More on security and governance controls

/ XGEN Platform

XGEN 3.0 platform architecture

An Enterprise AI platform that joins server-side control with local execution and carries plans, tools, and work context across environments without breaking continuity

Access · ConsoleUser mode (Chat/Assist)Admin modePortal / dashboardOpen-API · SDKSSO integrationAny device · one session
Vertical Domain
Domain and channel
Finance
Banking · capital · lending
Public sector
Government agencies
E-commerce
Home shopping · retail
Services
Media · content
Other
Private LLM
Agent & Application
Agents and applications
Harness Runtime
Goal interpretation · planning · tool selection · replanning
Business agents
Agents scoped to a task — support, document handling, approvals
Multi-Agent Orchestration
Planner → agent routing, extended stage by stage
Workflow Canvas
Compatible with existing low/no-code workflows
Hybrid Execution
Server ↔ local
Server Agent Runtime
Agent Logic
Planning · orchestration
LLM Gateway
Inference · model routing
Tool Runtime
Code execution · API calls
Workspace
Persistent files · state · history
SYNC
CONTRACT
Approved interaction
Local Interaction
Xgent Client
Secure connection boundary
Local Folder
Approved file access
OS Capability
Local apps · capabilities
Local MCP
Private-network tools
Server-side agentLeast privilegeState syncUser approvalImmediate stop
Platform Core
AI platform core
AI Service Generator
Service creation, deployment, and version management
Service configuration
On-demand GPU · LLM/ML · vector DB connections
LLMOps (Generative)
Model training, monitoring, evaluation, model switch and repo
Model Router
Multi-LLM routing optimized for cost and performance
MCP Catalog
Registry for server and local tools
Retrieval-Augmented
RAG and knowledge
DenseSparse (SPLADE)RerankerLate ChunkingVision / OCR

Document parsing → embedding → hybrid retrieval → rerank → context injection

Qdrant Vector DB
Dense + sparse hybrid index
Embedding · Parsing
Document parsing, OCR, and vectorization pipeline
Foundation Model
Foundation models
Open-source LLMs
Open models · private · vertical LLMs
Fine-tuning
SFT / DPO · domain-specific training
Multi-model extension
Model Router integration · vision · embedding models
Infrastructure
Infrastructure
k3s HA
Kubernetes high availability
ArgoCD
GitOps · zero-downtime deployment
Qdrant
Vector Database
MinIO
Object Storage
On-Premise
GPU · containers
Monitoring
Resources · performance · alerts
Governance & security

Cross-cutting control across every layer

Guardrail
Blocks prompt injection, harmful content, and confidential leaks
RBAC / ABAC
Role- and attribute-based access control with MFA
Approval Control
Pre- and post-approval for sensitive actions
Trace & Audit Log
Tracks plans, tools, files, and exports
Local Policy
Scope controls by folder, OS capability, and MCP
PII de-identification
Masking and pseudonymization of personal and financial data
Kill Switch
Immediately stops agents, sessions, and local connections
Compliance
Policy templates · validation · evidence
Reference deploymentsFinance (bank J, capital I) · e-commerce (home shopping L) · media (company I) · public agencies · enterprise
On-premise and air-gap ready

XGEN 3.0 runs on a Harness Runtime that turns goals into plans and a centrally governed Server Agent Runtime. Only when needed, Xgent Client connects approved local folders, OS capabilities, and MCP tools, then synchronizes results and state. Least privilege, user approval, execution traces, and an immediate kill switch extend the existing AI Platform Core, RAG, foundation-model, and infrastructure capabilities.

See the XGEN product

/ Code Assistant

Code Assistant architecture

Natural-language questions and code searches run through indexing, hybrid retrieval, and AI reranking to produce a code answer with evidence behind it

User (developer)
Natural-language question or code search
API server
Async processing
1
Indexing pipeline
Batch
  • Source collection and preprocessing
  • Indexing and embedding
Vector DB
Qdrant
2
Hybrid search
Keyword + vector
  • Keyword search (BM25)
  • Vector similarity search
Keyword index
BM25
3
AI rerank and answer
Re-rank + LLM
  • AI reranking
  • LLM answer generation
Code graph DB
PostgreSQL
Call and dependency relationships
Combined result
Relevant code, call and dependency flow, and an AI answer
See the XGEN DevStudio product

/ CI/CD

GitOps deployment pipeline

From source change to production — container image builds and declarative GitOps sync make each deployment a controlled one

Source
Branch and merge request
CI Build
BuildKit multi-stage image
Registry
Container image storage
GitOps Sync
Manual ArgoCD sync
Cluster
k3s · app and infra namespaces

GitOps and declarative

Git is the single source of truth — manifests define the cluster state and sync it

Controlled releases

Branch plus merge request required (no direct push to main), with manual sync controlling when a deploy lands

On-premise and air-gapped

Image export/import moves builds across the air gap, with per-site environment separation (dev/stg/prd)

Observability

Prometheus and Grafana monitor state, logs, and traces after deployment