local_only
The planned default keeps inference and working data on customer-controlled hardware with external model egress disabled.
Deployment modes / Local first
Local-only, API-only, and hybrid packages are planned but not yet in the download catalog. Before release, each adapter must declare its provider, budget, allowed data classes, and customer authorization.
Architecture published · packages pendingThe planned default keeps inference and working data on customer-controlled hardware with external model egress disabled.
The planned API mode requires a named provider, approved data classes, customer-owned credentials, and a defined budget.
The planned hybrid mode routes by task and data class with visible failover rules and no silent privacy downgrade.
A package cannot be released under the local-first label unless PII, confidential, or regulated material remains local by default and any external provider route requires explicit customer authorization and an appropriate agreement. Diagnostics and remote support must be off by default, scoped, visible, and revocable.
Next mission
See how public knowledge and private execution stay isolated.