Privacy by architecture, not by a vendor's policy page.
The landing page makes plain-language claims. This page substantiates them: the perimeter, the Router's three lanes, the Guards, and the Ledger — the same architecture in every edition.
Whose computer are your files on?
- ✕ Your private files leave your network with every paste
- ✕ Retention and training policies you don't control
- ✕ No log you can actually produce later
- ✕ For a covered business, that's not a habit — it's an exposure
FAMILY PHOTOS · CLIENT FILE
- ✓ Private data never leaves the building
- ✓ Local models by default; frontier models only through the gate, by your policy
- ✓ Every prompt, retrieval, and reply written to the Ledger
- ✓ Privacy by architecture, not by a vendor's policy page
Three lanes, one policy.
Every request routes by sensitivity. The local lane is the default: open models on the box, so private data never leaves. The Claude lane reaches frontier reasoning through the policy gate, when your policy allows. The cloud lane carries general tasks only. You set the policy once; the Router enforces it on every request.
Hardened against the ugly stuff.
Boring, tested, load-bearing.
Every action, written down.
Every prompt, retrieval, model response, and outbound message goes to an append-only log on the box. For a household that's peace of mind; for a covered business it's the evidence file — exportable as a document you hand an auditor.