Tenant-isolated
It may mean your data is kept apart from other customers'. It says nothing about who can sign in through a connector, who can support it or which model sees it.
Private retrieval-augmented generation
Private RAG is retrieval-augmented generation over your own approved sources. Marella grounds answers that way, and a privacy claim only means something once you can see where the documents are stored, which model reads them, who can get to them and who runs it.
Files, pages, passages
Pick the right passages
Which model runs, and where
Claims + source links
How RAG works
Search the approved documents for passages relevant to the question.
Choose which passages should enter the answer context.
Ask the configured model path to synthesise from that context.
Resolve material claims back to the passages presented as support.
Check source, version, support and remaining uncertainty.
Retrieval gives the model something to work from. It does not replace access controls.
Four words vendors use
It may mean your data is kept apart from other customers'. It says nothing about who can sign in through a connector, who can support it or which model sees it.
It tells you who owns the servers. You still need to write down who handles the model calls, the updates, the backups and support.
Names where the software package runs. It does not automatically mean on-premises, local models, air-gapped or zero-egress.
This is a promise in a contract. Ask which suppliers and which models it covers.
The private RAG worksheet
For each one, write down where it lives, who runs it, who can see it and how it gets deleted.
| Artefact | Questions to settle | Evidence |
|---|---|---|
| Source files | Storage, region, backup, deletion | Data-flow + retention record |
| Parsed text + embeddings | Store, isolation, rebuild, purge | Architecture + lifecycle test |
| Prompts + passages | Inference provider, transit, retention | Provider + contract coverage |
| Answers + traces | Event scope, access, export, retention | Event matrix + product inspection |
| Support artefacts | Access route, approval, expiry | Support responsibility split |
Test before you buy
A well-designed system can still pull the wrong passage, and a good answer can still travel a route you would not approve. Test both.
Known answers, plausible distractors, stale and conflicting sources
Citation correctness, completeness and no-answer behaviour
Cross-scope questions, revoked access, deleted content
Storage, inference, logs, backup, support and egress paths
Boundary conditions
Private RAG FAQ
Not necessarily. The term may refer to managed isolation, customer cloud, self-hosting or contractual controls. Name the actual architecture.
Current product legal materials state a no-training position for customer data. Confirm the relevant provider and contract coverage during procurement.
No. Retrieval changes what the model has to work from without making it correct, so an answer can still overstate or distort a passage that was retrieved perfectly well. Test whether the retrieved passages are relevant, whether the claims stay supported by them, and whether the system says so when the evidence is thin.
Map first, move data second
Do not submit confidential documents through the public form. Agree the transfer route during evaluation.
Plan a private RAG evaluation