Mode 2 — Client cloud
DocMark runs in your own cloud tenant — your Azure, AWS, or GCP — managed by you. Full AI authoring and research, on the LLM account you bring.
The promise
Everything on-prem does, plus AI — running inside your own cloud tenant. DocMark is deployed in your Azure, AWS, or GCP subscription and managed by your team. Your content stays inside your cloud boundary; it never enters DocMark’s infrastructure. AI authoring, drafting, chart derivation, agentic generation, and optional web research with cited sources all run there, on the LLM subscription you bring.
We will never call this mode “zero-egress” — because it isn’t. Content sent to your chosen model provider leaves DocMark’s process and reaches that provider through one governed channel, under your account and your contract. We think telling you that plainly is a feature.
Bring your own LLM
You bring the AI relationship; we publish the guidance. DocMark’s own authoring is one governed,
spend-capped call under your own account to the LLM provider you bring — Anthropic (Claude)
today, with OpenAI, Azure OpenAI, and Google Gemini on the roadmap. (Prefer another provider now? Your own agent can author with any LLM and
call DocMark’s /v1 API or MCP server to render — the branded render itself uses no LLM.) The key,
the spend caps, the data-processing terms, and the provider clearance are all yours.
How it works
- Your team submits a topic, a brief, or existing content — through the web app, the
/v1REST API, or your own AI assistant over MCP. In this mode, you run the/v1API and the MCP server yourself, inside your tenant. - DocMark makes one governed, spend-capped call under your own account (BYO key) to the LLM provider you bring — Anthropic (Claude) today; other providers on the roadmap. Your security team clears the provider directly; you set the spend caps; by default the provider does not use API data for training, and you confirm that in your own contract.
- The model authors the outline or researches the topic — web research returns cited sources that ship in the deliverable.
- Still inside your tenant: deterministic branded render (pixels never from AI), then the
visual-QA gate. Pass and it’s delivered with its
contract-protectedlabel; fail and it’s withheld with findings.
The BYO-LLM story, as a feature
- BYO subscription (recommended): the AI relationship is yours, on your paper, cleared by your security team — we never see your content’s API traffic or its terms.
- Your cloud boundary: content and rendering stay inside your tenant. DocMark is software you run, not a service your content is shipped to.
- Fail-closed attestation: if the data-processing attestation isn’t in place, AI authoring refuses to run. There is no “oops, it called the API anyway.”
- Machine-enforced labelling: the pipeline writes the egress class on every artifact. A
deliverable that touched a model can never carry a
zero-egresslabel.
Who it’s for
Teams whose content is confidential, but whose security organisation can accept running AI inside
their own cloud tenant under their own provider contract — and who want the productivity of AI
authoring, cited research, and a /v1 API plus MCP server they operate themselves, without giving
up local rendering, in-boundary verification, and audit-grade provenance.