Security · Nodes

VPC-Deployed AI Hiring with Zero Data Egress

Saad Bin Shafiq, Founder, NODES·Last reviewed May 28, 2026·Read the paper

VPC-deployed AI hiring runs entirely inside your own cloud environment, so candidate and employee data never leaves your infrastructure. NODES deploys as single-tenant software in your VPC or on-premise, with zero data egress and no calls to OpenAI, Anthropic, or any third-party model. Models are trained and hosted inside your environment, and you keep the keys and the controls. This is the architecture that lets security and legal teams approve AI hiring that ordinary SaaS tools cannot clear.

Source: The published Decision Traces study was conducted entirely inside the carrier's VPC, with no candidate data leaving its infrastructure at any point. Read it on arXiv.

What VPC deployment means

The software runs in your cloud, on AWS, Azure, or GCP, or on-premise. Your network, your keys, your access controls. There are no outbound calls to external services during scoring, screening, or training. The data stays where your governance rules require it to stay.

Zero data egress, no third-party models

No candidate data is sent out of your environment, and NODES does not route anything through OpenAI, Anthropic, or other external models. The models are trained and hosted inside your environment, and you own the resulting weights. Nothing about a candidate leaves your infrastructure to make a prediction.

Why this matters for regulated enterprises

Most SaaS AI hiring tools send data to external models, which fails data residency and vendor risk review. That is why legal and security teams block them. Running the AI inside your own VPC keeps data resident, supports your compliance obligations, and produces decisions you can audit. See why enterprises block external-API tools.

What is included

  • SOC 2 Type II controls and single-tenant isolation.
  • PII handling inside your environment and a full audit log of decisions.
  • No demographic data in the model, by design.
  • Standard connectors to your ATS and HRIS.
  • AWS GovCloud and Azure Government for public sector requirements.
  • Fully offline deployment for air-gapped or classified environments with no internet connectivity.

How deployment works

NODES maps your infrastructure and security requirements, deploys the stack into your VPC, configures the ATS and HRIS connectors with PII handling, and trains your model on your own historical data. You see the deployment plan before anything is provisioned.

Frequently asked questions

What is VPC-deployed AI hiring? AI hiring software that runs inside your own virtual private cloud, so data never leaves your environment and there are no third-party model calls.

Does NODES send candidate data to OpenAI or other models? No. There is zero data egress and no calls to external models. The models are trained and hosted inside your environment.

Can it run on-premise or in a government cloud? Yes. NODES supports AWS, Azure, GCP, AWS GovCloud, Azure Government, and fully offline deployments.

Is NODES SOC 2 compliant? NODES is SOC 2 Type II and deploys single-tenant inside your environment.

Related reading


See a deployment plan for your own environment. Book a 30-minute walkthrough.