← Lokus

Draft — pending legal review. Not binding.

Security Architecture

Lokus is designed to work with sensitive company data. The default behaviour is local; cloud-connected features stay off unless an administrator explicitly enables them.

Data flow

Files → local index → local model → answer/artifact. This entire flow happens on your device and requires no internet connection.

If a cloud-connected feature exists, it engages only with administrator approval and when explicitly enabled.

Deployment options

On-device, on-network, and air-gapped (no-internet) deployments are supported. After the initial model package, Lokus can operate fully offline.

Controls

Isolated (sandboxed) task execution · exportable audit trail · secrets stored in the OS keychain · explicit confirmation for sensitive actions.

Responsible disclosure

If you find a security issue, please contact us at [email protected].