The appliance is the only component that ever sees a prompt. It runs the LLM, the retrieval index, and the policy engine on hardware we ship to your office.
Disks are encrypted with TPM-bound keys. The OS is signed, the kernel is signed, and fleet updates roll out through the same signed-manifest pipeline.
Two variants today — a silent desktop Micro for small offices and a 1U rack-mount Starter for production floors — with a dual-GPU Pro configuration for 70B-class models.