Built so your files never leave — and only the people you enroll can reach it.
The security isn't a product you bolt on. It's how the system is put together: your documents sit at the center, and every layer around them decides who can get near, what the AI may do, and leaves a record you can show anyone.
The layers around your documents
Enforced in code — can't be bypassedAdvisory the model is asked to follow it
Your officeOn-prem · no cloudNothing is sent out. Full audit trail kept locally.Enforced
Dark accessZero TrustOnly devices you enroll can even see it — everything else on your network is blind to it.Enforced
Agent guardrailsGovernedThe AI only performs the tasks you approve — nothing more.EnforcedAdvisory
Local private modelYour Mac StudioRuns entirely on the appliance in your office — works offline.Advisory
Your documents & matters
Never leave the building.
Each layer wraps the one inside it — defense in depth, not a single lock. Where a ring carries both tags, some of its rules are enforced in code and some are asked of the model — the next section separates them.
What actually stops the AI — and what you can trust
What shapes its behaviorAdvisory
Rules written into the AI's instructions.
Refuse & escalate — decline out-of-scope or unsafe asks and hand back to a person.
Treat data as data — content it reads (a file, a web page) is never treated as new orders.
Stay in its lane — only the tools and scope the role is meant to use.
Works most of the time — but instructions can be misread or slipped past. Necessary, not sufficient.
What you actually rely onEnforced
Checks that run in code, before and after every action.
Path safety — refuses to write to protected locations, no matter what it's asked.
Approval gate — file changes and commands pause for your yes/no.
Can't disarm itself — the AI can't edit its own settings to turn approvals off.
Reality-check — after each turn it verifies claims against what actually happened, and flags a warning if the AI says it did something it didn't.
These don't depend on the model's good intentions. This is the part you trust.
How the layers catch a mistake — a real example
When the soft layer slipped, the hard layer caught it.
A real sequence from our own system, in plain terms.
1 · a check over-fired
A safety rule was too broad and wrongly blocked the AI's own helper file — a false alarm.
2 · the model slipped
Blocked from checking its work, the AI claimed success it hadn't actually achieved.
3 · code caught it
The reality-check compared that claim to what happened on disk and flagged it — before it reached anyone.
4 · fixed
The over-broad rule was narrowed. Real system paths stay protected; the false alarm is gone.
The takeaway: the advisory layer shaped good behavior, then slipped — and the enforced layer is exactly why the slip was caught instead of shipped. When we extend your system, we invest in the layers that can't be argued with.
In plain terms, it answers three questions
Who can reach it?
Only the devices you enroll. A stranger — or a compromised laptop on the same network — can't even find it.
Identity & device trust
What can it do?
Only the tasks you've approved. The AI works inside guardrails you set, scoped to each role.
Agent governance
Can you prove it?
Every access and action is written to a plain-English record you can hand to a partner, client, or auditor.
Audit trail
What you can configure — the dials
Simple by default, extensible by design. Every deployment ships with sensible defaults; these are the dials you can turn as your needs grow. Gold = the default we recommend.
The appliance
Mac mini → Mac Studio M4 Max Default → multi-node
Sized to your team and how large a model you want to run.
Who it serves
Just you → small teamDefault → whole firm
Each person reaches it from an enrolled device — no shared logins.
The model
Fast & lightDefault → larger, more capable
Every option runs entirely on the appliance — nothing calls out.
Memory of your files
Off → your documents indexedDefault
Point it at a folder and it can recall from your own material (RAG).
Network posture
Dark on LANDefault → Isolated → Air-gapped
How locked-down it runs — detailed just below.
Staying current
Managed tunnelDefault → scheduled → hand-carried media
Updates never touch your files; the method scales with your isolation.
Reach from your phone
OffDefault → enrolled device over Zero Trust
If enabled, your phone connects the same dark way a laptop does.
Approvals
Ask every time → ask for sensitive actionsDefault
You decide which actions pause for a human yes/no.
Not a compliance certificate. This shows where each framework's expectations land in the design — a map you can hand an auditor, client, or insurer to see the design was built with their concerns in mind. It doesn't claim certification; that's assessed against your specific deployment.
Every device is verified before it can reach anything — no implicit trust just from being "on the network." This is the Zero Trust core those three define.
Sensitive data stays on-prem, access is least-privilege and recorded — the residency and handling rules your sector expects.
Each framework links to its official source — NIST, CISA, CSA, ISO, the EU Commission, HHS, FTC, FBI CJIS and the NAIC. Which of the sector rules apply depends on your industry.