Case studies
Blue Mesh in production, told with the figures each customer reports in its own case study, and the organizations that run it and agreed to be named.
The customers we name publicly
Each of these organizations runs Blue Mesh and agreed in writing to be named. Netstratum and Voifinity are Netstratum-family brands: real deployments, not evidence of adoption outside the family.
- 01Vaspian
- 02Lonesome No More
- 03Voifinity
- 04Netstratum
The problem
Every customer conversation carries valuable intelligence and sensitive personal data. Vaspian saw the opportunity early: thousands of daily calls held rich insight on customers, sentiment and service quality that its traditional stack could not capture. Unlocking it meant AI that could operate on regulated communications data without compromising customer privacy, at the volume of a working telecom network rather than a pilot.
What we did
Vaspian chose the Blue Mesh Intelligence Layer, a speech-analytics and conversation-intelligence platform over its call recordings: AI transcription enriched with entity detection, speaker diarization, sentiment and intent, with personal data redacted automatically.
Results
- 01Around 950,000 AI transcript requests processed every month
- 02Around 38,000 hours of audio transcribed and analysed
- 03Customer PII protected through automated redaction
- 04Consistently high availability under sustained enterprise load
The problem
Lonesome No More set out to build an AI voice companion for seniors, a service whose conversations touch health information and deeply personal detail. The team evaluated the leading AI voice agents and, by its own account, found none that combined natural conversation with the privacy such data demands, so public, shared AI platforms were not an option. They needed a voice agent that feels human, on infrastructure private enough to be trusted, and one that could hold a conversation with an older person on an ordinary phone line: hearing difficulty, slower speech, long pauses that are not the end of a turn, and no screen to fall back on when the model gets it wrong. The case study sizes the market at 24 million seniors.
What we did
The answer was a custom-trained voice model in a dedicated private Blue Mesh instance, governed by safety guardrails, with conversations held inside it. Connected directly to the telephone network, the agents hold natural daily check-ins, remember prior conversations for continuity, and monitor wellbeing, escalating concerns to carers with a person deciding what happens next. Software only, no hardware in the home.
Results
- 01Reliable daily automated engagement
- 02Up to 60% cheaper than hardware-based alternatives
- 03After the initial capital investment, ongoing running cost stays low
- 04Health data and personal details are held inside the private instance
- 05Conversation history retained for continuity, with concerns escalated to a person who decides what happens next
What to check before a deployment
How an evaluation works
One working session on a workflow you already run, on a sample of your material, with your team holding the gate. What we need from you, and how pricing is set afterwards.
Where it runs and who is in control
Private cloud, on-premises or fully air-gapped. Role-based access, escalation to a person on the decisions that matter, and an audit trail your reviewer can read.
How Blue Mesh compares
Every platform on your shortlist held beside ours, cell for cell, from what each vendor publishes, with the questions worth putting to all of them, including us.
Compare us with any platform
An enterprise AI platform is a multi-year commitment. It will sit inside your environment, act in your systems, and answer to your auditors, so it should be chosen on the criteria that decide those things, not on the demo. Our own published answers come first; any platform's answers can be held beside them, cell for cell, from each vendor's own pages.
| Platform | Deployment | Multi-model | Voice | Human approval before an action | Published compliance |
|---|---|---|---|---|---|
| Blue Meshthis is us | Private cloud, on-premises, or fully air-gapped. BM in a Box is an air-gapped appliance on NVIDIA DGX. source | Yes source | Yes, over SIP source | Yes, every level source | Certifications your build can carry: SOC 2, ISO 27001, HIPAA. Every decision logged, role-based access, encryption. source |
| Sovereign orchestration | |||||
| Kamiwaza AI | On-premise, edge, cloud and air-gapped, including classified networks. No multi-tenant SaaS published. source | Yes source | Not published | Not published | Not published (no certification claimed anywhere on their site) |
| Operational platform | |||||
| Palantir AIP | AWS, Azure, Google Cloud, Oracle, on-premises, and disconnected/air-gapped. Multi-tenant vs single-tenant wording not published. source | Yes source | Yes source | Yes source | FedRAMP High, DoD DISA IL-5/IL-6, CMMC; HIPAA, GDPR and ITAR referenced. SOC and ISO referenced only generically. source |
| Suite platform | |||||
| IBM watsonx Orchestrate | SaaS on IBM Cloud, SaaS on AWS, on-premises via Cloud Pak for Data, local Developer Edition, and air-gapped. SaaS tenancy model not published. source | Yes source | Yes source | Not published (overview claims it; the node reference defines no approve/reject semantics) | Unverified (ibm.com returns HTTP 403 to automated fetch; the reachable developer docs name no certifications) |
| Microsoft Copilot Studio | Multi-tenant public cloud; GCC and GCC High government clouds; FedRAMP High; EU Data Boundary. True on-premise and air-gapped not published. source | Yes source | Yes source | Yes source | SOC, ISO 27001/27017/27018/27701, HIPAA BAA, FedRAMP, PCI DSS, HITRUST CSF, CSA STAR, UK G-Cloud, GDPR source |
| Salesforce Agentforce | Multi-tenant public cloud on Hyperforce. Single-tenant, private VPC, on-premise and air-gapped not published. source | Yes source | Yes source | Not published | SOC 2, SOC 3, C5 (ISAE 3000), PCI DSS AoC, ISO/IEC 27001:2022 source |
| ServiceNow AI Agents | Unverified | Yes (bring your own LLM, scoped to Now Assist rather than AI Agents specifically) source | Unverified | Unverified | Unverified (trust and compliance pages return HTTP 403) |
| Hyperscaler | |||||
| AWS Bedrock AgentCore | Multi-tenant AWS across 15 named regions, with VPC connectivity across all services. On-premise, GovCloud, sovereign and air-gapped not published. source | Yes source | Not published | Yes (approver not stated to be human) source | BIO, C5, CISPE, CPSTIC, ENS High, FINMA, GNS, GSMA, HITRUST, IRAP, ISMAP, ISO 27001/27017/27018/27701/22301/20000/9001, CSA STAR, MTCS, OSPAR, PCI, Pinakes, PiTuKri, SOC. HIPAA eligible; FedRAMP being pursued. source |
| Databricks Mosaic AI | Vendor-managed multi-tenant control plane on AWS, Azure and GCP, with customer-managed VPC and PrivateLink. On-premise not published. source | Yes source | Not published | Yes source | SOC 2 Type II, C5, CCCS Medium, DoD IL5, FedRAMP High and Moderate, HIPAA, HITRUST, IRAP, ISMAP, K-FSI, PCI-DSS, TISAX, UK Cyber Essentials Plus source |
| Google Vertex AI Agent Buildernow Gemini Enterprise Agent Platform | Not published / unverified | Yes source | Not published | Yes (via ADK component) source | ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3, PCI DSS, Penetration Testing, scoped explicitly to the named agent service. HIPAA and FedRAMP not on that page. source |
| Snowflake Cortex Agents | Fully managed inside the Snowflake account, with cross-region inference routing. On-premise and private connectivity not published on the product page. source | Yes source | Not published | Not published | Platform-wide list (CSA STAR L1, ISO 9001/27001/27017/27018, SOC 1 and 2 Type II, CJIS, DoD IL5, FedRAMP Moderate and High, GovRAMP, IRS 1075, ITAR, NIST 800-171, HITRUST, PCI DSS, IRAP, C5, TISAX AL3, K-FSI, CE+) with no per-feature scope stated. Only FedRAMP Moderate is explicitly scoped to Cortex Agents. source |
| Model provider | |||||
| Cohere (North) | Customer VPC, on-premise, or Cohere-managed Model Vault. Air-gapped not published. source | Yes (vendor blog only, not corroborated in docs) source | Not published | Yes (vendor blog only, no docs page defines the mechanism) source | SOC 2 Type II, scoped explicitly to 'our API platform' not to North. ISO 27001, ISO 42001 and HIPAA appear as badge images with no scope text. source |
| Mistral AI | Varies by product. Studio: hybrid, dedicated, self-hosted, cloud and on-prem. Le Chat Enterprise: self-hosted, customer public or private cloud, or Mistral cloud. API: regional endpoints EU or US. Air-gapped not published. source | Yes (limited: hosts one third-party open model so far) source | speech models yes; voice-agent and telephony not published | Yes (Mistral Work only, not Studio or Le Chat Enterprise) source | SOC 2 Type II, ISO 27001/27701 source |
| Enterprise assistant | |||||
| Aiseraacquired by Automation Anywhere | Unverified (security and platform pages now redirect off-domain to the acquirer) | Not published | Yes source | Yes source | Unverified on any Aisera-owned page |
| Ema | Runs entirely in the customer environment, fully isolated when required. source | Yes source | Yes source | Yes source | SOC 2 Type II, ISO 27001, ISO 27017, ISO 27701, ISO 42001, CSA STAR, GDPR, EU AI Act. HIPAA not published. source |
| Glean | Single-tenant, either Glean-hosted or in the customer's own AWS, Azure or GCP. Air-gapped not published. source | Yes source | Yes (in-app real-time voice; telephony not published) source | Yes source | SOC 2 Type II, ISO/IEC 27001, ISO/IEC 42001:2023, HIPAA, GDPR source |
| Moveworksacquired by ServiceNow | Regional AWS cloud including US GovCloud, EU, Canada, Australia, UK and Japan. Tenancy model not stated. source | Yes source | Not published | Yes source | ISO/IEC 42001, 27001:2013, 27017:2015, 27018:2019, 27701:2019; SOC 2 Type 2; CSA STAR Level 2; GDPR; CCPA; FedRAMP. HIPAA not published. source |
| Writer | Agent deployment via Docker to cloud, on-premises or local; AWS PrivateLink and GCP Private Service Connect for connectors. Core platform tenancy not published. source | Yes source | Not published source | Not published | Unverified (writer.com returns HTTP 403 to fetch) |
| Contact-center agents | |||||
| Cognigy | Managed Kubernetes on AWS EKS, Azure AKS or Google GKE (recommended). On-premise Kubernetes possible but explicitly discouraged and unsupported. source | Yes source | Yes source | Not published | Marketing-level list only: GDPR, ISO 27001, CCPA, HIPAA, SOC 2, PCI DSS. Trust centre unverified (JS-rendered, empty body). source |
| Cresta | Not published | Not published | Yes source | Yes source | SOC 2 Type II, SOC 3, ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 42001:2023, HIPAA, PCI DSS, GDPR, CCPA, CPRA, TISAX source |
| Decagon | Standard SaaS, single-tenant SaaS in a dedicated VPC, cloud-prem in the customer VPC, and on-premise datacentre by exception. Air-gapped described as bespoke, not a packaged tier. source | Yes source | Yes source | Not published | GDPR, CCPA, EU AI Act, HIPAA, SOC 2, ISO (no standard number published), PCI source |
| Forethoughtacquired by Zendesk | AWS infrastructure. Tenancy not published. source | Not published | Yes source | Not published | ISO 27001, SOC 2, HIPAA, GDPR, CCPA, alignment with NIST 800-53 and 800-171 source |
| Kore.ai | Public multi-tenant SaaS, private cloud dedicated VPC (single tenant), and on-premises. Air-gapped not published. source | Yes source | Yes source | Yes source | SOC 2 Type II, PCI DSS, ISO/IEC 27001:2022, GDPR, CCPA, EU AI Act, DESC CSP (trust centre). FedRAMP appears in docs but NOT on the trust centre. source |
| Parloa | Microsoft Azure with regional hosting and data-residency controls. Single-tenant vs multi-tenant not published. No on-prem published. source | Yes (including bring your own STT, TTS and LLM) source | Yes source | Yes source | ISO/IEC 27001:2022, ISO 17442:2020, SOC 2 Type 1, SOC 2 Type 2, PCI DSS, HIPAA, DORA, GDPR, EU AI Act source |
| Sierra | Not published | Yes (Sierra selects the blend; customer model choice not published) source | Yes source | Not published | SOC 2, HIPAA, GDPR, PCI Level 1, FedRAMP High, CCPA, CSA STAR, ISO 27001, ISO 42001 source |
| Teneo.ai | SaaS, private cloud, on-premise (on-prem corroborated by docs; air-gapped not published) source | Yes source | Yes source | Not published | ISO 27001, SOC 2 Type I and II, Cyber Essentials, GDPR / EU AI Act source |
| Yellow.ai | Not published source | Yes source | Yes source | Not published | SOC 2 Type II, ISO/IEC 27001:2022, ISO/IEC 27701:2019, HIPAA, PCI-DSS v4.0.1 source |
| Voice agents | |||||
| PolyAI | Not published source | Yes source | Yes source | Not published | ISO/IEC 27001, SOC 2 Type II, Cyber Essentials and Cyber Essentials Plus, HIPAA, PCI-DSS, GDPR source |
| Voice infrastructure | |||||
| Bland AI | Bland-managed cloud, your VPC, on-premise, air-gapped (all four named) source | No source | Yes source | Not published | SOC 2 Type I and II, HIPAA, GDPR, PCI DSS v4.0 source |
| Retell AI | Shared multi-tenant cloud; Dedicated Stable Server on Enterprise; deployment in the customer's own infrastructure. Private VPC and air-gapped not published. source | Yes source | Yes source | Not published | SOC 2 Type 1 and Type 2, HIPAA (signed BAA required), GDPR source |
| Vapi | Vendor-hosted cloud; on-premise for large enterprises. Private VPC and air-gapped not published. source | Yes source | Yes source | Not published | SOC 2 Type II, HIPAA (signed BAA required), GDPR, PCI source |
| Agent framework | |||||
| Botpress | Managed cloud; tenancy, VPC and on-prem unverified. Self-hosted docs page returns only a JS redirect stub. | Yes source | Not published | Yes (on outbound MESSAGES, not on tool actions) source | Unverified (security, enterprise and privacy pages all HTTP 403; trust portal Drata-hosted and also 403) |
| CrewAI | AMP is managed multi-tenant cloud; Factory is self-hosted on Helm/Kubernetes; on-premise stated on a vendor blog. Air-gapped not published. source | Yes source | Not published | Yes (on task output, not per tool call) source | Unverified (trust centre JS-rendered; no certification on any fetchable page) |
| Dust | Multi-tenant cloud SaaS. Self-hosted NOT published as a supported edition despite the MIT repo. Regions unverified. | Yes source | Not published | Yes (on state-modifying tool calls, with accept/reject links) source | SOC 2 (type not specified), GDPR. ISO 27001 and HIPAA not verified. source |
| LangChain / LangGraph | Platform: multi-tenant cloud, BYOC in the customer VPC, and self-hosted (both Enterprise). Regions GCP US/EU/APAC and AWS US. Air-gapped not published. Framework: self-hosted library. source | Yes source | Not published | Yes (per tool call, before execution) source | SOC 2 Type 2, HIPAA, GDPR. ISO 27001 unverified (trust portal JS-rendered). source |
| LlamaIndex | Framework is a self-hosted library. LlamaCloud offers SaaS, private VPC across all cloud providers, and self-hosting/BYOC on Kubernetes (terms password-gated). Air-gapped not published. source | Yes source | Not published | Yes (developer-built pause primitive, not a packaged product feature) source | SOC 2 Type II, GDPR, HIPAA, stated for LlamaParse specifically rather than the whole platform source |
| Lyzr AI | Lyzr Cloud SaaS, on-premise inside the customer VPC, and hybrid. Air-gapped not published. source | Yes source | Yes source | Yes source | SOC 2 Type II and ISO 27001:2022 have downloadable audit documents. HIPAA and ISO 42001:2023 are listed as programme standards with no report evidenced. source |
| Rasa | Self-hosted on own infrastructure, private cloud, and fully offline / air-gapped. Multi-tenant cloud not named. source | Yes source | Yes source | Not published | Vendor wording is hedged: 'supports SOC 2 Type II compliance'. Their security page claims controls 'aligned with ISO 27002' and names no achieved certification. source |
| Relevance AI | Multi-tenant cloud across US, EU and AU regions; region fixed at signup. Single-tenant stated to be in development. Self-hosted, on-prem and air-gapped not published. source | Yes source | Yes (outbound phone agent via Twilio; inbound not published) source | Yes (per tool, Approval Required mode with a drafted action) source | SOC 2 Type II, GDPR. HIPAA and ISO 27001 not published. source |
| Stack AI | Four deployment models spanning multi-tenant cloud through air-gapped on-premise; on-prem runs entirely in customer infrastructure on any major cloud or own servers. source | Yes source | partial (audio in and out; telephony not published) | Yes (workflow pause for human input) source | SOC 2 Type II, HIPAA, GDPR, ISO 27001 source |
| Vellum | Vellum Cloud managed, VPC on AWS/Azure/GCP, and self-hosted including environments without internet connectivity. source | Yes source | Not published | Not published | SOC 2 Type 2, HIPAA. GDPR and ISO 27001 not published. source |
| Voiceflow | Vendor-hosted cloud. Tenancy, VPC and on-prem not published. source | Yes source | Yes (native telephony) source | Not published | SOC 2 Type II, ISO/IEC 27001:2022, GDPR, HIPAA source |
| Automation | |||||
| Automation Anywhere | Customer VPC / private cloud, plus vendor cloud across 16 datacentres. On-premise and air-gapped not published. source | Yes source | Not published | Not published (referenced but never defined; approvals doc is gated) | SOC 1 Type 2, SOC 2 Type 2, SOC 3, ISO 27001, ISO 22301, HITRUST, GDPR, FIPS-140 encryption. HIPAA and FedRAMP not claimed. source |
| n8n | n8n Cloud is managed multi-tenant hosted in the EU on Azure; self-hosted is offered. Air-gapped and private VPC not verifiable on a fetched page. source | Yes source | Not published | Yes source | Cloud: SOC 2 alignment plus a public SOC 3 report, GDPR. Self-hosted: security is the operator's responsibility. ISO 27001 and HIPAA not published. source |
| UiPath Agentic Automation | Automation Cloud SaaS, Automation Cloud Dedicated (single-tenant), Automation Suite self-hosted, Automation Cloud Public Sector. Air-gapped not published. source | Yes source | Not published | Yes source | ISO 27001, ISO 27017, ISO 27018, ISO 9001, HITRUST; SOC 1, SOC 2, HIPAA, C5 attestations; FedRAMP for Public Sector; ISO/IEC 42001 and EU AI Act alignment source |
| Zapier Agents | Multi-tenant cloud only, hosted on AWS in the United States. VPC Peering is network connectivity to the customer VPC, NOT a customer-hosted deployment. No single-tenant, on-prem or air-gapped option published. source | Yes (verified for AI by Zapier; model choice within Agents specifically not published) source | Not published | Yes source | SOC 2 Type II, SOC 3, GDPR, CCPA. ISO 27001 and HIPAA not claimed. source |
| Vertical point agent | |||||
| Abridge | Not published | Not published | Yes (ambient capture, not telephony) source | Yes source | HIPAA, SOC 2 Type 1, SOC 2 Type 2, CCPA, TX-RAMP, WCAG. HITRUST and ISO 27001 absent. source |
| Eleos Health | Browser extension over any web-based EHR. Tenancy not published. source | Not published | Yes (ambient audio; telephony not published) source | Yes source | HIPAA, HITRUST, SOC 2 Type II, ISO 27001, ISO 27799, ISO 42001 source |
| Hippocratic AI | Not published | Not published | Yes source | Not published | HIPAA, SOC 2, HITRUST e1 (on-site badges only) source |
| Coding agent | |||||
| Cognition (Devin) | Cloud, with dedicated or on-prem for Enterprise; customer data stored in the customer tenant. source | Not published | Not published | Yes source | SOC 2 Type II, ISO/IEC 27001:2022, CCPA. No HIPAA, no GDPR listed. source |
| ITOps | |||||
| BigPanda | Not published | Not published | Not published | Not published | SOC 2 Type II; security framework described as ISO 27002:2013-based, which is alignment not certification. source |
1. Built from what each vendor publishes on its own website, with the source linked in every cell. Last updated 18 August 2026.
2. All product names and trademarks are the property of their respective owners; no affiliation or endorsement is implied.
- Voice agents Behind the Lonesome No More companion: low-latency voice over SIP, speech in and out, running on models you host.
- Telecom Vaspian's sector: call recordings transcribed and read for sentiment, quality and compliance risk.
- Platform overview The modules, capabilities and deployment modes behind both deployments, on one page.
Bring a workflow you already run
In one session we will build an agent for it, live, with your team holding the gate, so you judge the work rather than the references.