Where it runs

Your board pack is the most sensitive document in the company. So the first question is not what the tool does.

It is where the thing runs, who can reach it, and what leaves the building. There are four answers, and the same rule holds in all of them: your documents stay inside a boundary you control. What changes is where you draw it.

The four shapes

Same tool, four boundaries

One codebase runs in all four. The difference is not what it can do — it is who holds the key, who decides who signs in, and whether anything crosses the line at all.

Scroll the diagram sideways to read it all

Four ways to run the tool, and what leaves the boundary in eachOn a laptopTHE MACHINE ITSELFYour documentsThe toolFindings · reports— no model on this machine —Cleansed passages onlyto the model service you chooseKEYThe operating system holds it —Keychain or DPAPISIGN-INA workspace password, chosen on firstrunREACHNothing listens on the network. Oneperson, one machineOn a machine inside your networkYOUR NETWORKYour documentsThe toolFindings · reportsA private model, if you preferCleansed passages onlyor nothing at all, with a private modelKEYHeld by the machine, or by your ownsecret storeSIGN-INA workspace password, or yourdirectoryREACHYour network only. Your IT runs it; wehave no accessIn your own cloudYOUR CLOUD ACCOUNTYour documentsThe toolFindings · reportsClaude, inside your boundaryNothing leavesthe model runs inside the boundaryKEYYour key store, your customer-managedkeySIGN-INYour directory — Entra ID or Cognito,MFA requiredREACHYour account, your network, yourpoliciesIn a boundary we run for youA DEDICATED BOUNDARYYour documentsThe toolFindings · reportsClaude, inside the boundaryNothing leavesthe model runs inside the boundaryKEYA key store in that boundary, sharedwith nobodySIGN-INYour directory, MFA requiredREACHNo standing access for us — perincident, approved, time-boxed
The same application in four places. Read the row marked in colour: it is the only part that differs in substance.

One

On a laptop

An adviser, a chief of staff, one person doing the work. It installs like any desktop application and listens to nothing but itself — the browser tab is just the interface.

Suits a first engagement, a single company, work that has to start this week.

Two

On a machine inside your network

The same install on a machine your IT already manages, reachable by the people they say. Your backup policy, your patching, your disk encryption.

Suits a firm that wants the work in-house and has no appetite for a cloud project.

Three

In your own cloud

A dedicated instance in your own AWS account or Azure subscription. Claude runs inside that boundary through the cloud's own model service, so the documents never cross it.

Suits a firm with a cloud estate, a security team and a questionnaire to satisfy.

Four

In a boundary we run for you

The same architecture, in an account we operate on your behalf — one boundary per client. Not a shared platform with your name on a row: your own account, network, keys and model endpoint.

Suits a firm that wants the outcome without the deployment project.

Getting in

Sign-in belongs to your directory, not to us

On a laptop there is a workspace password, chosen the first time it runs, which the operating system's own keystore can hold for you. Everywhere else, the people who should reach it are already in a directory that handles joiners, leavers, MFA and conditional access — so that is what decides.

Scroll the diagram sideways to read it all

The checks a request passes before it reaches client dataRequestfrom a browserEdgeTLS, filteringYour directoryMFA, and the groupyou decideThe tool checksthe token itselfnot a header fromsomething in frontSession12 hours, thenback to the directoryClient dataencrypted at rest,with your keyEvery one of these is checked by the tool itself. It never assumes that something in front of it already did the work.
Microsoft Entra ID or Amazon Cognito, with the group you nominate deciding who may use the instance. When someone leaves, their access goes with their account. Nobody has to remember to tell us.

Where a directory is in front, there is no separate application password to share, rotate or forget — a second door is the thing the directory was brought in to close.

Your documents

What happens to the material you hand over

Four things, in the order they matter.

Names come out before anything is read

Customers, suppliers and people are replaced with stable cover names before a passage reaches a model, and the replacements hold across runs so the analysis still makes sense. It is defence in depth, not the only defence.

Passages, not documents

The tool sends the specific passages a question turns on, not whole board packs. In a cloud deployment even those stay inside your boundary, because the model runs there. Nothing is used to train anything.

Encrypted at rest, with a key you hold

Documents, extracted text, findings and the register can be encrypted whole-file with the workspace key. There is no vendor escrow and no recovery — we cannot open your data, which is the point, and also the risk you are accepting.

Every report is signed and checkable

Each issued PDF is stamped and registered, so a copy in circulation can be tested against what was actually issued: authentic, altered, or never issued at all. Board papers get forwarded.

The rules that do not bend

What we will not do, whichever shape you pick

  • No shared anythingOne client, one boundary. No shared database, no shared keys, no shared network. Whatever goes wrong anywhere, it goes wrong for one client.
  • No standing accessWhere we operate the boundary, support access is requested per incident, approved by you, time-boxed and logged. There is no permanent door with our name on it.
  • No training on your contentNot by us, and not by the model services the cloud deployments use.
  • No lock-inYour workspace exports whole, whenever you ask, in a form that opens on a laptop or in the other cloud. Leaving takes an afternoon.
  • No quiet claimsThe tool states what protection is actually in force rather than what is available. If encryption is off, or a document was never provided, it says so on the record.
  • No conclusions without evidenceEvery finding cites the passage it came from. A claim the documents cannot test is reported as untestable, not dressed up as an answer.

A fair question

What if no network call is acceptable at all?

Then run a private model on the machine. The tool supports one, the quality is lower and it says so, and nothing whatsoever leaves the boundary. Some material genuinely warrants that trade, and it is better made deliberately than discovered afterwards.

Not sure which shape fits?

Twelve questions, a few minutes, nothing stored unless you ask us to get in touch. It will tell you whether your strategy can be tested at all, which is the question underneath this one.

Take the readiness check