Local hosting allows a company to control its computing node, but it does not automatically protect data. Applications still have users, integrations, updates and backups. Design security around these access paths rather than the claim that everything sits in one box.
Map the movement of information
Record document origins, original-file storage, search indexing and answer recipients. List external connections separately: email, CRM, updates and approved AI services. This can reveal unexpected data transfers even when the model itself runs locally.
Include logs. Complete prompts and answers may contain the same sensitive information as source documents. Diagnostic records therefore also need access limits, retention periods and a defined purpose.
Example: two departments sharing a station
Procurement and HR may use one node with different document collections. Separation must apply to retrieval, file access and history. Hiding an HR navigation button is inadequate if the server still returns the material through a direct request.
Test as an ordinary user, not only an administrator. Try opening a known document link after its access has been revoked. Current permissions should govern the result, including saved answers and indexed material.
Assign operational responsibilities
- Who grants and revokes access? - Who holds recovery keys, and who can act in their absence? - Which external processing routes are allowed and visible to users? - Who maintains updates and handles incidents?
Treat recovery as a separate safeguard
CISA recommends offline encrypted backups and regular restoration tests. A copy on the same accessible device may fail with the original. CISA · Ransomware Guide (PDF) ↗
A pilot need not promise absolute security. It should document safeguards, test them and state their limits. For AI Office, that evidence belongs in technical acceptance alongside response quality and performance.