LocallyAI

Privacy and security

Private by default.
Exceptions written down.

The base setup is local and offline. That boundary changes only when you choose a feature that needs a connection. This page says exactly what stays in the building, what can leave, and what each install decides in writing.

No blanket “secure” claim · no hidden cloud claim · every exception named in writing

The base layout

The standard offline boundary

In the base offline configuration, prompts, documents, recordings and model inference remain on the customer's appliance.

Data may leave that appliance only through a feature or service the customer separately enables or requests: web research, updates, an external integration, remote support or off-site fine-tuning. The quote and configuration record identify the exceptions chosen for that install.

Network diagram: the machine connects to the office network, which connects four desks. The link to the outside internet is crossed out. the internet your machine office network reception consult room practice manager anyone else no connection to the outside internet required
This is the base offline layout. Approved research, update, integration, support and fine-tuning connections are recorded separately.
Proved controls

What the current build enforces.

These paths have been exercised in the current Harness rather than inferred from a screen or plan.

HTTPS on the office network
The Harness launches over an encrypted local connection at its local address.
Internet blocked by default
Outbound access is denied unless an administrator adds a specific allowlist rule.
Server-side ownership checks
Another user cannot fetch a private conversation or file by changing an identifier. The response is not found rather than a clue that the item exists.
Role and capability checks
People, administrator actions and staff capabilities are checked by the server, not just hidden in the interface.
Restricted tool workspaces
Small generated tools run in a limited environment rather than receiving broad access to the appliance.
Admin network controls
Administrators can manage people, network blocks and the operational record from the Harness.

Accounts

Private work stays out of normal admin views.

The Harness does not give an administrator a normal endpoint for reading another person's private conversations or personal files. Administrative views are for people, permissions, network controls and operational information.

The business still controls the physical appliance and its operating-system administrator access. That is a separate level of access and needs the same internal governance as any office server.

Shared workspaces are deliberate. Information barriers for stricter separation are included.

Connections

Every outside path has a reason.

Web research
Optional. The approved research plan can use the LocallySearch service when the web toggle is enabled.
Harness updates
A temporary connection is needed to apply and check an update. It is closed again when the work is done.
External integrations
Mail, business systems and other connected services can exchange data for the enabled workflow. The fields, direction and provider terms need to be recorded for that connection.
Remote support
A separate support session is started when the customer requests help. Ordinary use does not need a standing remote session.
Off-site fine-tuning
Only when separately requested. The agreed training material leaves the appliance for that job; on-site fine-tuning is a different option.
Install decisions

Some controls depend on the machine and office.

Mac, Windows and Linux builds do not use one identical disk, key and backup arrangement.

Disk encryption and keys

The platform-appropriate disk encryption, who holds recovery material and what happens after a power loss must be agreed and recorded for the supplied machine. We do not turn one operating system's control into a claim about every build.

Backup and restore

Backups run nightly, rotated and restorable, to the appliance or your own NAS. The installed target, retention, encryption and a recovery check still need to be proved for each customer configuration before that deployment is signed off.

Network and certificates

The office network must trust the local HTTPS certificate and keep the appliance on the agreed segment. Guest access, remote routes and allowlist entries are installation decisions, not defaults guessed from the website.

Reviewed at every visit

Security work with its status attached.

Decided per install

Information barriers, per-user settings, client-safe export, backup and restore, the health page, mail controls and the wider operational record are configured and proven per install as part of the acceptance checks.

Authentication acceptance

The quote names the authentication controls required for the deployment. We test enrolment, recovery, ordinary sign-in and the agreed account boundaries before handover; the acceptance record states exactly what passed.

Local does not mean infallible.

Generated text, citations, summaries and calculations can be wrong. A source link makes checking easier; it does not replace checking. Material legal, clinical, financial or business output still needs the source review and professional judgement the work normally requires.

One operating note on meetings: closing the browser tab ends its recording, and a locked phone can pause one. The complete feature page keeps that behaviour visible.

Bring us one job your team repeats every week. We will show you the system doing it →