Skip to content

On-Premise · Private AI · Data Sovereignty

Your data.
Under your control.

Self-hosted on your infrastructure. Company knowledge, processing, and optionally AI inference remain inside your network.

chifty / SECURITYInteractive illustration

Access starts with you. Identity and permissions.

Local data flows

A data path you control.

Data sources, permission checks, knowledge retrieval, and local AI form a controlled path inside your infrastructure. External endpoints are added only when you explicitly enable them.

  1. 01Data sources

    Emails, files, and company knowledge remain on your infrastructure.

  2. 02Permission check

    Roles, ACLs, and organization context determine which information is available.

  3. 03chifty

    The application processes only the context authorized for each request.

  4. 04Local AI

    A self-hosted AI model can perform inference inside your network.

  5. 05Authorized answer

    The answer uses only information the requesting user is allowed to access.

Private AI Mode

Fully local processing

With local models and locally operated services, no operational content leaves your company network.

Controlled Egress

Explicitly enabled AI endpoints

If you choose external models, only requests configured by you are transmitted to that endpoint.

Security by Architecture

Control is part of the architecture.

Access is not decided by a badge. It is enforced technically in every relevant data operation.

Data Sovereignty

The application, data layer, and local AI components reside in infrastructure controlled by you.

Customer-controlled infrastructure

Tenant Isolation

Data queries are consistently restricted to the active organization context.

Organization-scoped queries

Role-Based Access Control

Roles and capabilities govern administrative and organizational permissions.

RBAC · Capabilities

Fine-Grained Access Control

Access is additionally evaluated by user, owner, project, and permission level.

User · Owner · Project · Role

Permission-Aware RAG

Organization and document permissions are applied during knowledge retrieval.

ACL filtering before generation

Audit Trail

Administrative and knowledge-related activities are captured in audit and activity logs.

Local audit data

Private AI

Your models. Your rules.

You decide where inference takes place, which endpoints are reachable, and whether the AI path remains fully local.

Local Inference

Supported AI models can run within your own infrastructure.

Inference on your infrastructure

Model Sovereignty

You choose the model, endpoint, and network rules that apply to it.

Customer-selected endpoint

Zero Data Egress

With fully local models and services, no operational content leaves your network.

Fully local configuration

Controlled AI Endpoints

External models are accessed only through endpoints you explicitly configure and approve.

Explicit outbound path

Self-Hosted RAG Pipeline

Knowledge processing, vector search, and permission filtering can run on your infrastructure.

Local knowledge stack

Model Flexibility

AI access remains decoupled from a single model vendor and can be adapted to your environment.

Configurable model access

Identity & Access

The AI does not automatically see everything.

chifty considers organization boundaries and existing access rights when selecting relevant information.
01 · Tenant Context

Organization-bound requests

Every relevant request is associated with an active organization and user context.

02 · RBAC

Roles and capabilities

Administrative actions require the appropriate role and specifically assigned capability.

03 · Fine-Grained ACL

Content-level permissions

Projects, lists, documents, and content can carry additional user and owner permissions.

04 · Retrieval Guard

Permissions before the answer

Unauthorized knowledge entries are filtered during search, before the AI generates an answer.

Encryption & Application Security

Concrete measures. Precisely scoped.

We state the actual scope of every measure rather than making blanket security claims about all data.

TLS Encryption in Transit

Browser and application connections are protected by TLS during transmission.

Encrypted in transit

AES-256-GCM

IMAP passwords as well as booking and appointment tokens are stored with authenticated encryption.

Scoped credential encryption

Argon2id Password Hashing

Local passwords are hashed with Argon2id and are not stored in plain text.

Memory-hard password hashing

Parameterized Queries

Database access uses parameterized queries rather than client-composed SQL input.

No client-built SQL

Secrets Redaction

Tokens, cookies, and authorization headers are filtered from application logs.

Sensitive log controls

Offline License Verification

On-premise activation is verified locally and requires no ongoing connection to chifty.

No license server required

Operational Control

Your infrastructure. Your decisions.

On-premise does more than reduce data flows. It gives you control over operations and dependencies.

No Phone-Home

After setup, there is no ongoing data exchange with chifty servers.

Customer-Controlled Infrastructure

The network, storage, database, and runtime environment remain under your control.

Customer-Controlled Updates

You decide when supplied updates are installed within your operating processes.

Reduced Third-Party Exposure

With local AI, external AI and hosting providers are removed from the operational data path.

Infrastructure Independence

Your data and installation remain in your environment, even without ongoing vendor availability.

Private AI by design

Private AI starts with control.

Use AI with enterprise access control and local data processing—on your infrastructure and under your rules.

Book a demo

Frequently asked questions about on-premise security

What stays inside our company with chifty On-Premise?
The chifty application, data layer, and self-hosted knowledge components run on your infrastructure. If you also configure local AI models and local supporting services, operational AI processing can remain entirely within your network.
What does Zero Data Egress mean on this page?
Zero Data Egress applies to a fully local configuration: chifty, knowledge processing, required supporting services, and AI models then run in your network. If you explicitly activate an external AI endpoint, the requests configured for it are transmitted to that provider.
Can we still use external AI models?
Yes. You decide which AI endpoints may be reached. External models are a controlled option, not a requirement for fully local operation.
How does chifty prevent unauthorized AI answers?
Organization, user, and document permissions are applied during knowledge retrieval. Unauthorized entries are filtered before generation.
Does the on-premise installation require an ongoing connection to chifty?
No. Activation is verified locally. After setup, there is no ongoing data exchange with our servers.
Can chifty operate entirely without internet access?
Yes, when chifty is configured with self-hosted AI and all required local services. Some optional features may require external services and are therefore reviewed together before rollout.