cocoshedeStart blueprint

// PROCUREMENT_LAYER

Enterprise AI Vendor Catalog

Cocoshede blueprints reference infrastructure categories, not vendor hype. This catalog gives leaders a structured shortlist for the common procurement layers behind private, governed AI adoption.

VendorDeploymentCompliance postureOn-premBest fit
Vector database

Neon Postgres + pgvector

Strong fit for MVP and mid-market teams already comfortable with Postgres governance.

Managed cloud Postgres

GDPR: EU region available

HIPAA: Provider-dependent BAA review required

No

Teams that want a pragmatic vector layer close to relational application data.

Qdrant

Useful when sovereignty or self-hosting is a major buying criterion.

Cloud, private cloud, self-hosted

GDPR: EU hosting and self-hosting options

HIPAA: Enterprise review required

Yes

Private retrieval layers where teams need vector search portability and deployment choice.

Private inference hosting

vLLM

Requires internal ML platform maturity or an implementation partner.

Self-hosted / private cloud

GDPR: Customer-controlled deployment

HIPAA: Customer-controlled deployment

Yes

Serving open-weight models in private GPU environments with strong throughput requirements.

Managed model platform

AWS Bedrock

Strong candidate when the target architecture already lives in AWS.

Managed cloud

GDPR: Regional controls available

HIPAA: Eligible service review required

No

Enterprises standardizing AI adoption inside AWS procurement and security controls.

Azure AI Foundry

Evaluate when Azure AD, Purview, and Microsoft security tooling are already standard.

Managed cloud

GDPR: Regional controls available

HIPAA: Eligible service review required

No

Microsoft-centric enterprises requiring identity, governance, and procurement alignment.

Observability and evaluation

Langfuse

Important once prototypes move from demo usage into governed production monitoring.

Cloud, self-hosted

GDPR: EU and self-hosting options

HIPAA: Enterprise review required

Yes

Tracing prompts, model calls, evaluations, costs, and quality for production AI systems.

AI gateway

Cloudflare AI Gateway

Useful for teams pursuing hybrid API routing without building gateway infrastructure first.

Managed edge

GDPR: Regional and enterprise controls dependent on plan

HIPAA: Enterprise review required

No

Centralized routing, caching, observability, and policy control across model providers.

Security and output guardrails

Guardrails AI

Consider when report generation, extraction, or agent actions need deterministic gates.

Open-source, managed options

GDPR: Deployment-dependent

HIPAA: Deployment-dependent

Yes

Schema validation, output constraints, and policy checks around LLM workflows.

// PROCUREMENT_NOTE

How to Use This Catalog

Treat every entry as a due-diligence starting point. Enterprise buyers should still validate data residency, contractual terms, support coverage, security documentation, and implementation ownership before selection. Cocoshede links blueprint recipes to categories so teams can compare realistic options without turning strategy into a vendor shopping exercise too early.