Why Enterprise AI Agents Belong in Your Own Cloud

AI agents that work directly within your cloud environment. Keep your data, models, and intelligence under your control.

Stochastic / Blog

Why Enterprise AI Agents Belong in

Your Own Cloud

Enterprise AI agents need access to business data to do useful work. They may need to read sensitive documents, pull information from multiple systems and create new records. All of that data needs to remain protected throughout the process. This creates an important infrastructure challenge: how can AI agents work with sensitive business data while companies remain in control of where that data is stored and processed?

At xMagic, we solve this with a control and compute plane architecture. It separates the management of the AI platform from the infrastructure where agents actually work with your data. In this post, we explain how this architecture works and how it allows enterprises to deploy AI agents while keeping sensitive business data within the environments they control.

Agents handle more than the original question

A request to an agent can expose much more information than the words entered into a chat. Preparing a prior authorization packet, meaning the request and its supporting documents, may involve reading clinical notes and insurance details that the employee never copies into the conversation. The agent’s draft can then contain a summary of those records or passages taken directly from them. Protecting the original files therefore covers only part of the work, because the prompts sent to the model and the responses it creates may contain equally sensitive information.

An agent may also pass information to connected services or leave copies in conversation history and troubleshooting logs. A document held in a private database can still leave that environment when an external model processes an extract from it. Our article on moving AI agents into production describes data residency as a foundation for deployment. In practice, that means following the content through the whole task, including model processing and storage of the result, to identify which services receive it.

Each provider that receives that content introduces another set of data handling terms to review. Some AI services may use conversations or uploaded files to improve models, depending on the product, account settings and signed agreements. Personal accounts and enterprise services can have different rules even when they come from the same provider. Before connecting business records, the organization should establish whether its information can be used for training and whether people can access it for review or support. This matters for customer information as well as internal documents, since the organization remains responsible for the commitments it made when collecting that data.

A promise not to train on data does not explain how long a service retains it or what happens when the customer asks for deletion. Content from an uploaded file may remain in conversation history, troubleshooting logs or backups after the original upload is removed. Teams need to understand those retention periods and whether connected services keep their own copies. Reducing the number of systems that receive business content makes these responsibilities easier to manage, which is why xMagic separates the information needed to operate the platform from the records its agents use.

How xMagic separates control from compute

xMagic makes that separation through two layers, called the control plane and the compute plane. Your team connects through xmagic.ai to use the application. Stochastic operates the control plane and stores only platform metadata and usage information in its databases. The compute plane runs in your cloud, where agents execute tasks using your databases and storage for files, queries and AI responses. This allows Stochastic to manage the platform without keeping your business content in its databases.

Because xmagic.ai is also the interface through which users submit requests and view results, that content passes transiently through the control plane so it can be routed and displayed. Stochastic does not store this content in the control plane. It acts as a management and visualization layer, while prompts, responses, files and other business content remain stored in the customer’s cloud.

Where the model runs matters just as much as where your records are stored. With xMagic, Stochastic models can process your records in your cloud without Stochastic retaining the content or using it to train its own models. You can use this option without having to host or operate the models yourself, although you can also choose to bring a suitable open source model and run it in the same environment. Both options let the model generate answers within your cloud, so the information it needs stays there instead of being sent to an external model provider.

How xMagic handles a request

When a staff member asks xMagic to prepare a prior authorization packet, the agent retrieves the relevant patient records and insurer requirements from the connected sources. It passes that information to the model along with instructions for preparing the request. This work takes place in xMagic’s compute plane in the healthcare organization’s cloud, where both the agent and the model run in this example. During task execution, the production controls in xMagic provide guardrails, isolated execution and human approval for sensitive actions. The model processes the clinical notes and other records there to draft the request, identify supporting evidence and flag missing information, without sending those inputs to an external model provider. The agent then assembles the draft and supporting documents into the packet within that same compute plane.

The data created during this work stays in the same environment as the source records. The staff member’s query, the information provided to the model, its response and any subsequent corrections remain in the customer’s cloud, with files and results stored in the customer’s databases and storage. Stochastic’s control plane records only platform metadata and usage information, without retaining this business content or using it to train Stochastic’s own models. Using a record to generate an answer does not itself train the model on that record, since this is a separate optional process. The completed packet is submitted manually outside xMagic.

Fine tuning with your own business knowledge

Fine tuning trains an existing model further on examples of the behavior you want it to learn. Stochastic prepares those examples from the feedback and corrections your team makes while working with the agent, so staff do not need to build a separate training dataset. For instance, repeated edits to the way an agent organizes supporting evidence provide examples of the format staff need. When the customer chooses fine tuning, those corrections can be used to prepare training data within the customer’s cloud, where the original feedback also remains. The results can then be checked against the same requirement: whether new drafts follow the format with fewer staff corrections.

This is an optional process for improving the customer’s own model within its environment. It does not give Stochastic permission to reuse customer information to train its own models or models for other customers. The feedback, training examples and resulting model files stay in the customer’s cloud, with access governed by the permissions agreed for that work. The customer decides whether to enable fine-tuning and which feedback is appropriate to use. Everyday use of the agent therefore does not mean that every conversation automatically becomes training material.

Before an updated model is used in production, its outputs should be compared with the current version on cases that were not used for training. For prior authorization preparation, the comparison could check whether the draft cites the correct evidence, flags missing documentation and needs fewer corrections. A model that produces cleaner prose but changes a fact has not improved the workflow, so factual accuracy matters alongside the time saved in review. The organization can retain the tested version if an update performs worse. Current patient records and insurer requirements should still come from maintained sources, because fine tuning improves how the model handles a task rather than keeping its knowledge of changing records up to date.

Your institution’s own intelligence

With xMagic, Stochastic manages the control plane while agents, models and business data remain in your cloud. Optional fine tuning uses feedback from your team to improve models within the same environment. The result is your institution’s own intelligence, adaptive to how it works and confined to the environment it controls. To explore how this private intelligence infrastructure would work for your organization, talk to the Stochastic team about deploying xMagic in your cloud.