Privacy
Private by default is an architecture, not a policy paragraph
2026-08-26 · 8 min read
If the corpus is privileged, regulated, or simply none of a vendor’s business, the first design question is where the Knowledge Image lives. Not which model is trendy. Not which chatbot UI looks like a Series B.
HIVE systems are designed to sit on-prem, in a customer VPC, or air-gapped. Knolo images are portable so they can travel as artifacts, not as a SaaS default. Model serving, when it exists, is private. Logs stay with the environment that produced them. Offline verification is first-class.
US companies routinely underestimate European privacy because they treat GDPR as a banner and a DPA. Transfer mechanisms, subprocessors, retention, and access logs are engineering constraints. The cheapest compliance strategy is architectural restraint: do not collect, embed, or ship what you do not need.
Air-gap is not a slogan. It means no phone-home, updates as controlled artifacts, and a week planned as air-gap — not “we’ll figure it out Wednesday.” If we cannot honor the constraint, we refuse the work.
Bootcamp inherits the same rule. The corpus stays in the named environment: your VPC, your racks, or a HIVE isolated environment scoped to that week. Access is named, logged, and torn down.
We will not claim FedRAMP, IL5, or defense authorizations we do not hold. Operators who need those should hear a no early, while it is still cheap.
Private by default is how teams that cannot afford theater keep their files. The public chatbot is a non-starter. The convenience cloud is often a non-starter too. Say the constraint on intake.
If this is your failure mode, Bootcamp is the next step — not a newsletter.
Start a Bootcamp