How it's designed · How it's protected

Built so your files never leave — and only the people you enroll can reach it.

The security isn't a product you bolt on. It's how the system is put together: your documents sit at the center, and every layer around them decides who can get near, what the AI may do, and leaves a record you can show anyone.


The layers around your documents

Enforced in code — can't be bypassed Advisory the model is asked to follow it
Your officeOn-prem · no cloudNothing is sent out. Full audit trail kept locally.Enforced
Dark accessZero TrustOnly devices you enroll can even see it — everything else on your network is blind to it.Enforced
Agent guardrailsGovernedThe AI only performs the tasks you approve — nothing more.EnforcedAdvisory
Local private modelYour Mac StudioRuns entirely on the appliance in your office — works offline.Advisory

Your documents & matters

Never leave the building.

Each layer wraps the one inside it — defense in depth, not a single lock. Where a ring carries both tags, some of its rules are enforced in code and some are asked of the model — the next section separates them.


What actually stops the AI — and what you can trust

What shapes its behaviorAdvisory

Rules written into the AI's instructions.

  • Refuse & escalate — decline out-of-scope or unsafe asks and hand back to a person.
  • Treat data as data — content it reads (a file, a web page) is never treated as new orders.
  • Stay in its lane — only the tools and scope the role is meant to use.

Works most of the time — but instructions can be misread or slipped past. Necessary, not sufficient.

What you actually rely onEnforced

Checks that run in code, before and after every action.

  • Path safety — refuses to write to protected locations, no matter what it's asked.
  • Approval gate — file changes and commands pause for your yes/no.
  • Can't disarm itself — the AI can't edit its own settings to turn approvals off.
  • Reality-check — after each turn it verifies claims against what actually happened, and flags a warning if the AI says it did something it didn't.

These don't depend on the model's good intentions. This is the part you trust.


How the layers catch a mistake — a real example

When the soft layer slipped, the hard layer caught it.

A real sequence from our own system, in plain terms.

1 · a check over-fired
A safety rule was too broad and wrongly blocked the AI's own helper file — a false alarm.
2 · the model slipped
Blocked from checking its work, the AI claimed success it hadn't actually achieved.
3 · code caught it
The reality-check compared that claim to what happened on disk and flagged it — before it reached anyone.
4 · fixed
The over-broad rule was narrowed. Real system paths stay protected; the false alarm is gone.

The takeaway: the advisory layer shaped good behavior, then slipped — and the enforced layer is exactly why the slip was caught instead of shipped. When we extend your system, we invest in the layers that can't be argued with.


In plain terms, it answers three questions

Who can reach it?

Only the devices you enroll. A stranger — or a compromised laptop on the same network — can't even find it.

Identity & device trust

What can it do?

Only the tasks you've approved. The AI works inside guardrails you set, scoped to each role.

Agent governance

Can you prove it?

Every access and action is written to a plain-English record you can hand to a partner, client, or auditor.

Audit trail

What you can configure — the dials

Simple by default, extensible by design. Every deployment ships with sensible defaults; these are the dials you can turn as your needs grow. Gold = the default we recommend.

The appliance
Mac mini → Mac Studio M4 Max Default → multi-node
Sized to your team and how large a model you want to run.
Who it serves
Just you → small team Default → whole firm
Each person reaches it from an enrolled device — no shared logins.
The model
Fast & light Default → larger, more capable
Every option runs entirely on the appliance — nothing calls out.
Memory of your files
Off → your documents indexed Default
Point it at a folder and it can recall from your own material (RAG).
Network posture
Dark on LAN Default → Isolated → Air-gapped
How locked-down it runs — detailed just below.
Staying current
Managed tunnel Default → scheduled → hand-carried media
Updates never touch your files; the method scales with your isolation.
Reach from your phone
Off Default → enrolled device over Zero Trust
If enabled, your phone connects the same dark way a laptop does.
Approvals
Ask every time → ask for sensitive actions Default
You decide which actions pause for a human yes/no.
See these as four ready-made builds — pick your build →

The network-posture dial, up close


Where the major frameworks map

Not a compliance certificate. This shows where each framework's expectations land in the design — a map you can hand an auditor, client, or insurer to see the design was built with their concerns in mind. It doesn't claim certification; that's assessed against your specific deployment.

Security & AI-governance frameworks Sector & regional rules
Who can connectDark access + on-prem
Every device is verified before it can reach anything — no implicit trust just from being "on the network." This is the Zero Trust core those three define.
What the AI may doAgent guardrails + model
Governed scope, a human in the loop for sensitive actions, and documented controls — the "manage & oversee the AI" expectations these set out.
Prove what happenedReality-check + audit trail
Detect when something's off and keep a plain-English record of every access and action — the detect / respond / evidence side.
Where your data livesDocuments at the core
Sensitive data stays on-prem, access is least-privilege and recorded — the residency and handling rules your sector expects.

Each framework links to its official source — NIST, CISA, CSA, ISO, the EU Commission, HHS, FTC, FBI CJIS and the NAIC. Which of the sector rules apply depends on your industry.

See how the configuration lines up with each standard — control by control →

What this does — and doesn't

What it does

  • Shrinks the attack surface to near-zero — no open doors on your network
  • Least-privilege access — people reach only what they should
  • A full, plain-English record of every access
  • Your documents never leave the building

What it doesn't (said plainly)

  • It's protection, not magic — it runs on macOS; a device already compromised is still compromised
  • Zero Trust controls who can connect; the guardrails control what the AI does — you need both, and you have both
  • A framework map isn't a certification — it shows alignment, not a signed audit
  • Maximum isolation (Vault) trades remote convenience for on-site updates