"Your data never leaves the building" is the kind of line that sounds great and means nothing until someone explains it. Marketing pages love it. So let me do the unglamorous thing and describe what it actually means, step by step, because the difference from cloud AI is concrete and it matters.
Follow a single question
Imagine an employee asks the assistant to summarise a contract. With a cloud tool, here is the journey that question takes. The contract and the question leave their laptop, travel across the public internet, arrive at a provider's data centre (often in another country), get processed on machines nobody at your company will ever see, and the answer travels back. Somewhere in that trip, your contract sat on someone else's computer. Maybe it was retained for a while. Maybe it was used to improve a model. You are trusting a contract and a policy that the contract stayed private.
Now the local version. The employee asks the same question. The contract and the question go to a server sitting in your own building, on your own network. The model runs there. The answer comes back. Nothing crossed the internet. Nothing landed on a machine you do not own. There was no third party in the loop to trust, because there was no third party. That is the whole difference, and it is not subtle.
What "the building" really refers to
The phrase is a bit literal. What we mean is your trust boundary: the network and hardware you control. For most customers that is a server in their office or their own data centre. It can be genuinely air-gapped, with no internet connection at all, for the most sensitive work. Or it can be connected for convenience but configured so that the AI workload itself never sends data out. The point is that you decide where the edge is, and the sensitive processing happens inside it.
A quick way to test any "private AI" claim, including ours. Ask one question: when I submit a prompt, does the text of that prompt ever travel to a computer the vendor controls? If the answer is yes, in any form, for any reason, then the data does leave the building, whatever the brochure says. If the answer is no, ask them to show you how they would prove it.
Why this is more than a feeling
Keeping data local is not just reassuring. It removes real, specific problems. There is no international data transfer to assess against the shifting rules that followed the Schrems II ruling. There is no foreign statute that can reach a server which never held your data. There is no provider that could log your prompts or change its retention policy next quarter. When a regulator, an auditor or your own security team asks the hard question, where does the data go, you get to give the shortest possible answer. It stays here.
We seal the network perimeter on boot, keep an immutable log of what the system did, and ship the tooling to demonstrate that nothing left. That is the machinery behind the slogan. But the slogan itself is simple, and it is the reason a lot of our customers picked local AI in the first place. Their most valuable data is exactly the data they cannot send away. So we built the version where they do not have to.
