Data location
Lokalaise
Your infrastructure, on sitePublic cloud AI
Third-party data centersModels, knowledge layer, and workflows run on-premise — no cloud, no external APIs. Every answer is permission-checked and traceable.
01The perimeter
Models, knowledge layer, and agents live inside your own infrastructure — no cloud, no external APIs, no detours.
No external APIs, no third-party hosting, no data leaving your network.
blocked
Your network · your infrastructure
Inference, indexing, and storage happen exclusively on hardware that sits on your premises — operable fully air-gapped, without any internet connection.
02Permission-aware
Lokalaise checks permissions down to the document level — before an answer is generated. Even for salary data and personnel files: anyone without access rights never sees the content. Try it yourself.
Question to the knowledge layer
“Which salary band is on file for the site management role?”
Who is asking?
Role “HR · Personnel data” authorized · grounded answer
For the site management role, salary band E11: €68,000–82,000 gross per year is on file, plus the project allowance under §4 of the company compensation agreement.
HR is authorized for personnel data — so the knowledge layer answers, backed by source, version, and audit path.
No access · answer blocked
No access — salary data requires HR authorization. Project management has no access rights to personnel data. No answer is generated, no preview, no workaround — nothing leaks through.
Permission required: “HR · Personnel data”03Local vs. cloud
Public cloud AI sends your content outside. Lokalaise does not — the difference shows in every row.
Lokalaise
Your infrastructure, on sitePublic cloud AI
Third-party data centersLokalaise
Local, on your hardwarePublic cloud AI
Via external APIsLokalaise
Permission-aware down to the document levelPublic cloud AI
Coarse, often without source attributionLokalaise
Complete · source, version, historyPublic cloud AI
Limited, vendor-dependentLokalaise
Compliant — data never leaves your companyPublic cloud AI
Risk from third-country transfersLokalaise
Operable entirely without internetPublic cloud AI
Internet connection mandatory| Criterion | Lokalaiselocal · on-premise | Public cloud AIgeneric · external |
|---|---|---|
| Data location | Your infrastructure, on site | Third-party data centers |
| Inference | Local, on your hardware | Via external APIs |
| Permissions | Permission-aware down to the document level | Coarse, often without source attribution |
| Audit trail | Complete · source, version, history | Limited, vendor-dependent |
| GDPR | Compliant — data never leaves your company | Risk from third-country transfers |
| Air-gap capable | Operable entirely without internet | Internet connection mandatory |
04Auditable
Trust doesn't come from the model — it comes from the evidence. Every answer ships with source, version, history, and audit path.
4.1
Every statement shows the underlying document, page, and section — one click to look it up.
4.2
Answers reference a specific document version. Older states remain traceable, changes stay visible.
4.3
Who asked what and when, which sources were used, who had access — fully logged and exportable.
4.4
Unlike generic RAG, Lokalaise doesn't produce plausible guesses. Without authorized evidence, there is no answer.
Governed Knowledge: Source, permission, version, and audit path aren't optional — they are built into every answer.
05Compliance & standards
No promises — properties. These building blocks are included in the managed local stack, delivered and operated.
Data processing exclusively under your control — no third-country transfers.
Models, index, and storage run on hardware that sits on your premises.
Confidential content is stored strongly encrypted at rest.
Internal connections are secured end to end to current standards.
Existing roles and permissions are respected down to the document level.
Operable in isolated networks entirely without an internet connection.
Queries, sources, and access are logged without gaps.
Information security processes aligned with ISO 27001 are being established.
06Common questions
The key points on data sovereignty, operations, and compliance — answered clearly.
Security & data sovereignty
Let us show you what permission-aware knowledge, audit trails, and air-gapped operation look like in your environment.
100% locally operated · GDPR-compliant · no cloud, no external APIs