Draft — pending legal review. Not binding.
Security Architecture
Lokus is designed to work with sensitive company data. The default behaviour is local; cloud-connected features stay off unless an administrator explicitly enables them.
Data flow
Files → local index → local model → answer/artifact. This entire flow happens on your device and requires no internet connection.
If a cloud-connected feature exists, it engages only with administrator approval and when explicitly enabled.
Deployment options
On-device, on-network, and air-gapped (no-internet) deployments are supported. After the initial model package, Lokus can operate fully offline.
Controls
Isolated (sandboxed) task execution · exportable audit trail · secrets stored in the OS keychain · explicit confirmation for sensitive actions.
Responsible disclosure
If you find a security issue, please contact us at [email protected].