Privacy by architecture, not by a vendor's policy page.

The landing page makes plain-language claims. This page substantiates them: the perimeter, the Router's three lanes, the Guards, and the Ledger — the same architecture in every edition.

・the perimeter

Whose computer are your files on?

・the router

Three lanes, one policy.

Every request routes by sensitivity. The local lane is the default: open models on the box, so private data never leaves. The Claude lane reaches frontier reasoning through the policy gate, when your policy allows. The cloud lane carries general tasks only. You set the policy once; the Router enforces it on every request.

EVERY REQUEST, ROUTED BY SENSITIVITYLOCALCLAUDECLOUDPOLICY GATESET ONCE · ENFORCED ALWAYSDEFAULT · OPEN MODELS ON THE BOXPII: LOCAL ONLYBY POLICY, THROUGH THE GATEFRONTIER REASONINGGENERAL TASKS ONLYNEVER SENSITIVE LANES
・the guards

Hardened against the ugly stuff.

✓ Prompt-injection hardening on tool-using workflows
✓ Loop guards — the box can never ping-pong with another auto-responder
✓ Echo guards — it never replies to itself
✓ Per-contact rate caps

Boring, tested, load-bearing.

・the ledger

Every action, written down.

Every prompt, retrieval, model response, and outbound message goes to an append-only log on the box. For a household that's peace of mind; for a covered business it's the evidence file — exportable as a document you hand an auditor.

Evidence exportAir-gap capable