Egress clarity
Narrate precisely what crosses the WAN per prompt - not hand-wavy promises about mystical vaults.
Your working tree stays local. You choose what crosses the wire: cloud inference sends the prompt and attachments you authorize; local models keep tokens on your VLAN.
Tie every sensitive workspace to a concrete posture: what may egress, which subprocessors activate, where local inference is mandated, and who signs off.
Boundary decisions: - Default model path: Hosted (fast iteration) - Regulated subtree /ledger: LOCAL ONLY · Ollama 70B - Subprocessors consulted this sprint: • Inference vendor A · EU region pinned • Notification webhooks disabled for this cohort Operational notes: - Secrets never pasted into hosted prompts (vault refs only) - Screenshots embargoed unless security approves egress Sign-off before rollout: Security lead + Compliance PM + Repo owner
Narrate precisely what crosses the WAN per prompt - not hand-wavy promises about mystical vaults.
Classify repos, ban raw secrets inside prompts, and tie human approvals to merges the way you audit today.
Legal still owns DPIAs - surface subprocessors per workspace posture so questionnaires stop freezing launches.
High-signal placements
Finance, health-adjacent, public sector, and any shop that subtitles AI decks with subprocessors spreadsheets.
Hosted models
Egress DPIA appendixLocal inference
Ollama / LM StudioSecrets hygiene
Vault refs vs pasteCustomer data
Yellow / red classesCross-functional
Security + compliance + EMRepeatable playbook security and compliance can cite.
Green, yellow, or red - whatever taxonomy already governs source control.
Pin LAN-only stacks to local models; loosen only where DPIA paperwork already exists.
Export posture notes and subprocessors snapshots into questionnaires or architecture reviews.
No wholesale upload - you work against the tree you opened. Anything you cite or attach is intentional context; scope prompts accordingly.
Yes after you provision local endpoints and strip cloud credentials from sanctioned profiles Central IT publishes the pattern.
Assume they egressed once a hosted model processed them. Teach vault references and pair with scanners in CI.
They become multimodal payloads for whichever model replies - treat screenshots like pasted plaintext when customer data appears.
You do under your agreement - OSS and IP hygiene stay your counsel’s domain just like handwritten patches.
Pick one customer-data repo, classify it, route risky subtrees locally, capture subprocessors, revisit after one steady sprint.
Use the same Kodus plans, tokens, and routing controls whichever posture you enforce.
For individual usage.
For small teams.
For larger organizations.
Have invite code? Get Access Now