The four shapes
Same tool, four boundaries
One codebase runs in all four. The difference is not what it can do — it is who holds the key, who decides who signs in, and whether anything crosses the line at all.
Scroll the diagram sideways to read it all
One
On a laptop
An adviser, a chief of staff, one person doing the work. It installs like any desktop application and listens to nothing but itself — the browser tab is just the interface.
Suits a first engagement, a single company, work that has to start this week.
Two
On a machine inside your network
The same install on a machine your IT already manages, reachable by the people they say. Your backup policy, your patching, your disk encryption.
Suits a firm that wants the work in-house and has no appetite for a cloud project.
Three
In your own cloud
A dedicated instance in your own AWS account or Azure subscription. Claude runs inside that boundary through the cloud's own model service, so the documents never cross it.
Suits a firm with a cloud estate, a security team and a questionnaire to satisfy.
Four
In a boundary we run for you
The same architecture, in an account we operate on your behalf — one boundary per client. Not a shared platform with your name on a row: your own account, network, keys and model endpoint.
Suits a firm that wants the outcome without the deployment project.
Getting in
Sign-in belongs to your directory, not to us
On a laptop there is a workspace password, chosen the first time it runs, which the operating system's own keystore can hold for you. Everywhere else, the people who should reach it are already in a directory that handles joiners, leavers, MFA and conditional access — so that is what decides.
Scroll the diagram sideways to read it all
Where a directory is in front, there is no separate application password to share, rotate or forget — a second door is the thing the directory was brought in to close.
Your documents
What happens to the material you hand over
Four things, in the order they matter.
Names come out before anything is read
Customers, suppliers and people are replaced with stable cover names before a passage reaches a model, and the replacements hold across runs so the analysis still makes sense. It is defence in depth, not the only defence.
Passages, not documents
The tool sends the specific passages a question turns on, not whole board packs. In a cloud deployment even those stay inside your boundary, because the model runs there. Nothing is used to train anything.
Encrypted at rest, with a key you hold
Documents, extracted text, findings and the register can be encrypted whole-file with the workspace key. There is no vendor escrow and no recovery — we cannot open your data, which is the point, and also the risk you are accepting.
Every report is signed and checkable
Each issued PDF is stamped and registered, so a copy in circulation can be tested against what was actually issued: authentic, altered, or never issued at all. Board papers get forwarded.
The rules that do not bend
What we will not do, whichever shape you pick
- No shared anythingOne client, one boundary. No shared database, no shared keys, no shared network. Whatever goes wrong anywhere, it goes wrong for one client.
- No standing accessWhere we operate the boundary, support access is requested per incident, approved by you, time-boxed and logged. There is no permanent door with our name on it.
- No training on your contentNot by us, and not by the model services the cloud deployments use.
- No lock-inYour workspace exports whole, whenever you ask, in a form that opens on a laptop or in the other cloud. Leaving takes an afternoon.
- No quiet claimsThe tool states what protection is actually in force rather than what is available. If encryption is off, or a document was never provided, it says so on the record.
- No conclusions without evidenceEvery finding cites the passage it came from. A claim the documents cannot test is reported as untestable, not dressed up as an answer.
A fair question
What if no network call is acceptable at all?
Then run a private model on the machine. The tool supports one, the quality is lower and it says so, and nothing whatsoever leaves the boundary. Some material genuinely warrants that trade, and it is better made deliberately than discovered afterwards.
Twelve questions, a few minutes, nothing stored unless you ask us to get in touch. It will tell you whether your strategy can be tested at all, which is the question underneath this one.