Skip to content

How Locai One is secured

This page is for security, procurement, and IT leads. It describes what Locai One guarantees, not how Locai OS is built. Day-to-day screens: Security and support.

Locai One is a single-organisation appliance. It is not a shared service for many customers, and it is not a general-purpose computer that people log into. People use the Locai App. Administrators use the Admin Console.

Topic What we do
Data at rest Stored data is encrypted and bound to this appliance. A drive removed from the box is not usable as ordinary files.
Data in transit Locai App, Admin Console, and API traffic are encrypted in transit.
Network Workloads that hold data and run models are not exposed on your LAN. Your network only reaches the published HTTPS surfaces (and a support session, if you approve one).
Internet Off until IT turns it on. When it is on, only the destinations you have chosen: updates, a public certificate for a hostname you control, opt-in status reports, or an approved support session.
Sign-in Password plus authenticator app for every person. Accounts live on this box. No default password. No pairing code.
API keys Belong to one account, shown once, revocable. Optional expiry.
Admin Locai App-only accounts cannot open the Admin Console.
Support Locai engineers get remote access only when an administrator opens a session. It expires and can be revoked. Grants and sessions are logged.
Organisation Locai Labs is ISO/IEC 27001 and Cyber Essentials certified.
  • Prompts, replies, files you store, and model weights stay on this appliance.
  • Inference runs on this box. Answers are not fetched from a public AI provider.
  • Treat chat and files as organisation data, the same way you treat email.
  • Activity in the Admin Console records sign-ins and sensitive admin actions (users, network, support, factory reset). Usage and traces are also available there. Do not assume conversation bodies are omitted from on-box storage.

There is no separate backup-and-restore product. Chat, files, accounts, and models live on this appliance. A factory reset removes them. Keep copies of anything you cannot afford to lose, using your organisation’s usual process. Software Updates can return the appliance to the previous Locai OS version if an update fails; that is not a substitute for a data backup.

Path What happens
At rest Data on the appliance is encrypted. The secret that unlocks it is bound to this machine, not left as a passphrase on the disk.
In transit The Admin Console, Locai App, and API are reached over HTTPS.
Office network The certificate is issued by the appliance. Install the box CA on managed devices.
Company hostname A public certificate, after you enable Direct DNS.
Surface How you prove who you are Where the session lives
Admin Console Username, password, authenticator app Browser
Locai App The same account The device’s secure store
API A personal API key Your tool’s secret store

There is no default password on a new appliance. The first administrator is created in the first-boot wizard, with two-factor authentication enrolled before they leave. Username, password, and authenticator all stay on this box.

Session rule What it means
Idle (Admin Console) After 30 minutes without activity, the session ends.
Absolute (Admin Console) A session does not last more than 12 hours, even if someone stays active.
Locai App The session is held in the device’s secure store. Administrators can deactivate the account or revoke keys at any time.

Administrators reset passwords and authenticators under Users. Those actions appear in Activity.

  • A key is bound to one person. It is not a shared organisation secret.
  • The secret is shown once at creation. It is not stored in recoverable form. It cannot be displayed again.
  • Administrators and the key owner can revoke it. Create a replacement after a leak.
  • You may set an expiry when the key is created. Expiry cannot be edited later; revoke and issue a new key instead.
  • Services that hold data and run models are not published on your LAN. They communicate inside the appliance.
  • What your office network can reach is the HTTPS Admin Console, Locai App, and API.
  • The appliance is meant to work without the public internet.
  • It does not open outbound internet on its own. IT enables that. Your own firewall can still restrict those destinations on top.

Access from the internet stays off by default. If IT publishes a company hostname (Direct DNS), traffic is browser to your DNS to this appliance. Locai is not in that path.

Role Admin Console Locai App
Administrator Full day-to-day control Optional
Locai App (people with an account) No Yes
Locai Support (when present) Read-oriented for diagnosis n/a

People with a Locai App account cannot open admin pages. You cannot remove the last administrator. Add another first.

Locai does not have standing remote access to your appliance.

  1. An administrator starts a time-bounded session under Support in the Admin Console, with a reason for the audit trail.
  2. Only during that window can Locai engineers connect. People in your organisation never receive host access.
  3. The grant expires. The administrator can revoke it sooner.
  4. Opening, using, and closing the session is logged. Credentials for that session stay in the console. Do not paste them into tickets or chat.

Diagnostics packages from Support are sensitive operational data. Factory reset lives under General.

Locai Labs holds ISO/IEC 27001 and Cyber Essentials. Those certifications describe how we run the company. They do not replace the appliance controls on this page: data and inference still stay on this box.

  • Do not paste live support session secrets into tickets or chat.
  • Do not leave public access on if nobody needs it.
  • Do not share API keys in email.
  • Do not ask people to click through certificate warnings; install the box CA instead.