Privacy & security

Local by design. Precise about limits.

We reduce unnecessary data movement, give infrastructure control back to the customer, and state the trust boundaries that remain.

01

Process close to the source

Images, operational state, and sensitive context can remain on the device or customer site. Local operation reduces dependency and exposure; it does not make the device or site invulnerable.

02

Minimize the dataset and the report

Models receive only the context their contract requires. Portable views and exports contain a deliberate subset rather than a convenient copy of the private record.

03

Let the customer control infrastructure

Storage, retention, deletion, export, update windows, and connectivity can be aligned to customer policy and operating constraints.

04

Design offline as an operating mode

Air-gapped and intermittently connected systems need explicit paths for signed updates, evidence export, time, recovery, and physical administration—not simply a disconnected network cable.

05

Sign what crosses a trust boundary

Applications, models, recipes, references, and configuration can travel with provenance and signatures. Signatures establish origin and integrity; they do not prove that software is vulnerability-free.

06

Make failure visible

Unknown trust roots, malformed model output, incompatible hardware, failed health checks, and stale state stop the affected transition or fall back to a declared limited mode.

Explicit threat boundaries

What local processing does not solve by itself.

Every engagement develops its own threat model. Common boundaries include physical access, compromised endpoints, malicious updates, supply-chain faults, copied bearer documents, operator mistakes, browser extensions, ingress infrastructure, and unavailable recovery credentials.

Local ≠ anonymous

The system still handles data and may remain subject to privacy, contractual, or sector obligations.

Signed ≠ safe

A valid signature authenticates the publisher and bytes, not the correctness of every behavior.

Offline ≠ maintenance-free

Isolated systems still need patch intake, clock and key lifecycle, backup, audit, and attended recovery.

AI ≠ authority

Consequential policy and operator responsibility stay outside the neural model unless separately justified.

This public website

No tracking layer.

The site is static. It sets no cookies, runs no client JavaScript, loads no remote fonts or third-party assets, embeds no analytics, and has no contact-form backend.

Visiting still makes an ordinary HTTPS request to the hosting infrastructure. Network and security infrastructure may retain operational request records under its own administration; this site does not add user profiling on top.

Start with the constraint

Need a system with a stricter trust boundary?

We can design for local, outbound-only, intermittently connected, or air-gapped operation and make the maintenance path part of the architecture.