There is a category of work where the conversation about AI ends early, and it does not end for the reasons people expect. Not cost. Not capability. Not scepticism about whether the technology is any good.
It ends because the material is not the holder's to share.
Holding something on someone else's behalf
A great deal of valuable material is held rather than owned. Somebody gave it to you for a purpose, and that purpose did not include handing it to a third party so that a machine could read it.
The obligation might come from a contract you signed, a duty attached to the kind of work you do, an undertaking given to a client, or simply a promise made to a person who trusted you. The source varies. The consequence does not: you cannot unilaterally decide that sending it somewhere else is fine, because it was never yours to decide.
This is why the usual reassurances land badly with people in this position. Assurances about retention and encryption are answers to a question they are not asking. Their question is whether the material leaves at all, and the honest answer from a hosted service is that it does, because it has to be read somewhere.
The quiet compromise most people make
Faced with that, almost everyone does the same thing. They use AI for the material that does not matter, and keep the material that does out of it.
The general correspondence goes in. The client work does not. The marketing copy goes in. The file does not. It is a reasonable compromise and it has an obvious cost: the assistant is helping with the easy part of the job and is excluded from the part where help would actually be worth something.
Over time this produces a quiet cynicism about the whole category — the sense that AI is fine for drafting a newsletter and irrelevant to real work. That conclusion is correct about hosted AI and wrong about AI, and the difference between those two statements is entirely a question of where the computer is.
What changes when nothing leaves
If the machine that reads the material is in your own building, and the material never travels, the obligation question changes shape.
You are no longer asking whether you may share material with a third party, because you are not sharing it with anyone. The material stays where it already was, held under the same arrangements it was already held under, and a machine you control reads it in the same room.
We are not going to tell you that this resolves every obligation, because obligations differ and we are not the right people to interpret yours. What we will say is narrower and, we think, more useful: the hardest version of the problem — the material must not leave — is answered by an arrangement where it does not leave.
The questions worth taking to whoever advises you
If this is your situation, these are the questions that actually decide it. They are worth putting to the person who advises you on such things rather than to a vendor, including us.
- Where is the material permitted to be processed, and by whom?
- Does a machine reading it count as disclosure under the arrangements you are under?
- Who is permitted to hold a copy, and for how long?
- What must you be able to demonstrate afterwards about what happened to it?
- What are you required to tell the person the material concerns?
Notice that none of those is a technical question. They are all questions about your obligations, and the technology is only relevant insofar as it changes the answers.
What we will and will not claim
We will claim this: with the appliance in your building, your material does not leave it, the model trained on your material is yours alone, and nothing is pooled with anyone else's or used to improve any other model. Where you ask for an outside model to be consulted, that happens only when you open the valve, for as long as you open it.
We will not claim that this makes you compliant with anything, because compliance is a judgement about your circumstances that we are not in a position to make. Anyone who tells you their product makes you compliant is selling you a conclusion they are not qualified to reach.
Questions to ask before anything sensitive goes in →
Every promise we make, in plain words →
Local AI. Private data. Local training.
$8,995 the first year — everything included. $4,995 each year after. The first year costs more because it contains the Jetson Orin placed and configured, your archive loaded and the first training run; every year after is the service running.
Or add the Archive Assessment first — $1,950, credited in full
You order and pay at checkout; we write back within days — a decline returns every dollar, and until our letter confirms the year you may withdraw in writing. From that letter the year is final, and it arrives on the date the letter names. Prefer to write to us first?