Technical Specifications
Trend Micro Vision One™ AI Application Security: Self-Hosted Protection for Private Cloud & On-Premises AI Environments
For organizations in regulated industries — government, defence, financial services, healthcare — sending AI model data to a public cloud is not an option. Trend Micro Vision One™ AI Application Security for Private Cloud solves this. It delivers the same enterprise-grade LLM protection as the SaaS edition, but entirely within your own private cloud, on-premises data centre, or air-gapped environment. Your data never leaves your perimeter — not even metadata.
This is the self-hosted deployment of AI Application Security, built on the Trend Vision One™ platform. It gives your security team complete control over where AI scanning runs and where results are stored, without compromising on detection capability or coverage.
Key benefits for security and IT leaders:
- 100% data jurisdiction and control: All scan data, AI model inputs, outputs, and results — including metadata — stay within your designated environment. Nothing leaves your perimeter. Ideal for sovereign, air-gapped, and restricted-connectivity deployments.
- Self-hosted AI Scanner: Deploy and run the AI Scanner entirely in your own private cloud or on-premises environment. Scans AI models for common attack techniques, attack objectives, and harmful or sensitive content in inputs and outputs.
- Self-hosted AI Guard: Deploy and integrate AI Guard within your own environment to intercept malicious inputs and block potentially harmful outputs from your AI models — preventing exploitative usage and maintaining regulatory compliance without cloud dependency.
- Pre-deployment vulnerability scanning: Simulates real-world attacks — including prompt injection and data leakage scenarios — against your AI applications before go-live, fully within your network boundary.
- Real-time runtime guardrails: Continuous protection that blocks malicious prompts, harmful content, and sensitive data exposure from within your private infrastructure — no performance impact, no external calls.
- OWASP Top 10 LLM coverage: Covers 9 of OWASP’s Top 10 LLM security risks, including prompt injection, data leakage, and AI supply chain risks — enforced entirely on-premises.
- Flexible deployment architecture: Optimised for air-gapped, offline, private cloud, and data centre environments. Supports restricted-connectivity and isolated architectures for regulated or sovereign deployments.
- Unified Vision One platform: Managed through the same Trend Vision One™ console as all other solutions — one dashboard for AI risk scoring, threat visibility, and centralized monitoring across your entire environment.
- Regulatory compliance ready: Designed to meet GDPR, CCPA, data localization, and sector-specific compliance requirements that prevent data from crossing jurisdictional boundaries.
Who is this for?
- Government and defence agencies operating in classified or air-gapped networks
- Financial services and banking institutions with strict data residency obligations
- Healthcare organizations subject to HIPAA, PIPEDA, or regional health data laws
- Enterprises with sovereign cloud mandates or private data centre investments
- Any organization deploying LLM-powered applications where data must never leave the perimeter
Licensing — traditional per-term licensing for private cloud:
AI Application Security for Private Cloud is licensed under Trend Micro’s traditional per-term model. Please note: TrendAI™ Flex credits are currently available for SaaS solutions only and do not apply to customer-hosted or on-premises deployments. Licensing is scoped to your specific environment — number of AI applications, LLM instances, and deployment scale — and is provided via a custom private offer. Contact us for a tailored quote.
Onboarding — get up and running in 8 steps:
- Step 1 — Work with your Trend Micro sales representative to scope your private cloud deployment and obtain your licence certificate.
- Step 2 — Register your business in the Customer Licensing Portal (CLP) using the activation link in your licence email.
- Step 3 — Accept your licence terms and activate your Vision One console within your private cloud or on-premises environment.
- Step 4 — Choose your deployment region and configure your private hosted Vision One console for your environment.
- Step 5 — Deploy the self-hosted AI Scanner in your private cloud or on-premises environment following Trend Micro’s deployment guide.
- Step 6 — Deploy and integrate the self-hosted AI Guard within your environment to begin intercepting malicious inputs and blocking harmful outputs.
- Step 7 — Connect your LLM-powered applications to the self-hosted AI Guard via API and configure scan policies, content filters, and alert thresholds.
- Step 8 — Review AI Scanner scan results from your Vision One console dashboard — all data remains within your perimeter throughout.
Order Now
Secure your private cloud AI applications with Trend Micro Vision One™ today. Get expert support and the best pricing. Contact us.
| Security capability | Private Cloud (self-hosted) | SaaS (Trend-hosted) |
|---|---|---|
| Pre-deployment AI vulnerability scanning | ✓ | ✓ |
| Real-time prompt injection blocking | ✓ | ✓ |
| Data leakage prevention | ✓ | ✓ |
| Runtime attack protection | ✓ | ✓ |
| OWASP Top 10 LLM coverage (9 of 10) | ✓ | ✓ |
| AI Security Posture Management | ✓ | ✓ |
| 100% data stays within your perimeter | ✓ | — |
| Air-gapped / offline environment support | ✓ | — |
| Sovereign & data residency compliance | ✓ | — |
| Self-hosted AI Scanner deployment | ✓ | — |
| Self-hosted AI Guard deployment | ✓ | — |
| TrendAI™ Flex credit licensing | — | ✓ |
| Fully managed infrastructure | — | ✓ |

