The decisions we made before the first line of code.
Privacy, security and where intelligence physically runs are architecture choices. Made at the start, they are commitments. Made at the end, they are marketing.
Six decisions, taken once.
-
Shared spine, not copy-paste
Reasoning, memory, identity and permissions are built once and used by everything. A fix or a hardening lands everywhere at once.
-
On-device first where it is possible
If a task can run on the device, it runs on the device. Less latency, less exposure, less dependence on a connection.
-
Least data, not most
We collect what a capability requires and not the adjacent things that might be useful later. Retention is a setting, not a default.
-
Explainable where it counts
Any decision with a material consequence carries a trail of what informed it.
-
Degrade honestly
When the system is unsure, it says so. A confident wrong answer is the most expensive thing an AI product can produce.
-
Hardware only when justified
We build silicon-integrated products when latency, privacy or a missing sensor make software alone a compromise — never for the sake of an object.
Three boundaries, and you choose.
| Boundary | What it means | Typically for |
|---|---|---|
| On device | Processing happens on the hardware in front of you. Nothing leaves. | Latency-critical work, sensitive contexts, offline use |
| Private deployment | Runs inside your own cloud or infrastructure, under your controls | Enterprises with residency, regulatory or contractual constraints |
| Our cloud | Runs on our infrastructure, encrypted in transit and at rest, with configurable retention | Everything where the above is not required |
What we hold ourselves to.
Encryption in transit and at rest. Role-based access with least privilege. Audit logging on every access path. Secrets managed, never embedded. Independent review before anything material ships. Vulnerability disclosure taken seriously and answered.
The limits we put on ourselves.
We do not build systems whose purpose is to manipulate attention or behaviour against a person’s interest. We do not train on customer data without explicit, revocable permission. We test for failure modes that affect people unevenly, and we treat a system that is confidently wrong as a defect rather than a limitation.
Ask us the hard question.
If your security team has a question this page did not answer, send it. We would rather answer it now than in a procurement cycle.