Data residency
Prompts, retrieved context, outputs, corrections, and training data
are written to local storage on the node and never leave it. There is
no replication target outside the building.
Update channel
Outbound-only. The node pulls signed artifacts from a fixed endpoint
and verifies them against a key pinned at install. Nothing outside can
open a connection inward.
Telemetry
Metrics only — utilization, temperature, error counts, adapter version,
gate pass/fail. Never prompt content, never output content, never a
record identifier. The schema is fixed and published.
Air-gapped mode
Supported. The update channel is disabled entirely and artifacts
arrive on physical media against a published hash. Roughly a quarter
of prospects choose this.
Written to be forwarded to third-party risk without editing.