Your network is the starting point.
The intended customer architecture keeps model inference, document parsing, embeddings, retrieval, histories, logs, and backups on your premises. External model fallback is disabled. Optional integrations are identified and approved separately.
A strong platform. Carefully configured.
Apple silicon provides a foundation that includes secure boot and the Secure Enclave. We plan encrypted storage, least-privilege access, managed updates, and recovery procedures with your IT team. Hardware capabilities must be paired with configuration and operating controls.
Evidence before assurances.
Acceptance should include an egress-blocked workflow test, access-boundary checks, offline startup, model loading, and backup restoration. Availability and recovery commitments belong in the deployment agreement and must reflect tested capacity.
Supports your compliance program.
On-premises hosting does not remove HIPAA obligations, establish SOC 2 assurance, or guarantee compliance. Your legal and security teams determine the requirements that apply. We help document the deployment controls and responsibility boundaries.
Your control extends to support.
Remote support access is explicitly scoped. Updates, model imports, diagnostics, and backups need approved processes. The goal is a system you can understand and operate, with access you can revoke.
A separate boundary for sales.
This website, Google Workspace email, iMessage, and the sales qualification assistant are separate from the customer appliance. Do not send sensitive operational records through public sales channels. See our sales-site privacy notice.