Secure and Public AI
Two deliberately separate environments — confidential work never leaves your network, everyday work stays fast and flexible.
Powerful AI, without surrendering your data
The core design principle is separation. Your confidential material — contracts, financial records, HR files, client data — lives in a Secure Internal Environment that runs an open-weight model entirely on hardware you own. No query, document or answer ever leaves your network.
Alongside it, a General-Use Environment handles non-sensitive work like marketing copy, public research and brainstorming, with an optional connection to leading commercial models (Claude, GPT, Gemini) when extra capability helps. Content rules warn or block users before anything confidential reaches an outside model.
How the two stay separate
The boundary is enforced several ways at once, so a single mistake cannot leak protected data: confidential documents sit in a separate, internal-only collection the general-use environment cannot reach; the option to use an outside model exists only in the general-use environment, never in the secure one; department permissions control who can open which environment; and all activity is logged for review.
Service areas
Secure Internal Environment
An open-weight model, document store and long-term memory running entirely on your own server — for anything confidential or regulated.
General-Use Environment
An everyday-productivity environment for non-sensitive work, with optional access to leading commercial models under clear guardrails.
On-Premise AI Server
A dedicated GPU server sized for 100 users with headroom — model, document index and memory all on hardware you control.
Document Intelligence & Memory
Retrieval over your own documents plus long-term memory, so the AI answers from your material — not the open internet.
Access, Permissions & Logging
Department-based permissions decide who can open which environment and which documents, with activity logged for review.
Secure Remote Access
An encrypted, private tunnel lets approved staff use the platform from laptops and phones without exposing the server to the public internet.