A brain that remembers everything should live where you decide.
Intelain accumulates the most sensitive thing your company has: what happened, what was decided, and why. So the first question is not what it can do. It is where it runs, and what is allowed to leave. You choose, and the choice is enforced by architecture rather than promised in a contract.
Four places it can run
We host it
The fastest start. We run and maintain the platform; you connect sources and begin. Each company is isolated, everything is encrypted at rest and in transit, and your data is never used to improve anything we sell.
Your own tenant
The whole platform inside your cloud account, in the region you choose. Your subscription, your network, your keys. We deploy and support it; the boundary is yours.
Your servers, no internet
An isolated network segment with deny-by-default egress: no public address, no outbound route, private endpoints only. Your team reaches it over the internal network. Nothing traverses the internet.
One disconnected machine
The desktop application bundles the whole stack into one installable app: the interface, the API, the worker, the database, the query engine, the indexes and the language layer, all bound to the local loopback. No server, no network dependency.
Most companies mix them: a hosted or on-premise brain for the organisation, desktop installs for people who work where connectivity is not guaranteed, and an opt-in synchronisation between them that you control and can scope per person or device.
We do not share your data. There is no mechanism to.
Never used for training
Your data trains nothing. Not our models, not anyone else's. The brain learns about your company, inside your company, and that learning goes nowhere else.
No telemetry
No usage beacons, no analytics, no crash reports carrying your content. In an isolated deployment there is no configured outbound endpoint at all, so there is nothing to switch off.
No one in the path
In a self-hosted or on-premise deployment, no third party sits in the run-time path of your data. Support access, if you want it, is time-boxed, audited and granted by you.
Verify it yourself
In an isolated deployment, "nothing leaves" is something your own monitoring can confirm. Egress rules, flow logs and a packet capture will show zero outbound connections in normal operation.
That last one is the point. This is an auditable property of the deployment, not a promise you have to take on trust.
The thinking can happen inside your walls too
Every security review reaches this question, and it deserves a real answer rather than a reassurance. You choose where the reasoning runs, and you can change that choice later without changing how anyone works.
Your own endpoint
Point Intelain at the model service your organisation already runs and has already approved. Nothing goes anywhere your policy does not already permit.
Local, on your hardware
Open-weight models on a machine you own: a server with an accelerator for a team, or the workstation itself for one person. Questions, retrieved context and answers never leave the machine, because no external service is configured.
A managed service
With no residency constraint this is the simplest option. Your content is not used for training, and moving in-house later changes nothing about how the brain works.
Local models trade some capability for absolute containment: a model on one workstation will not match the strongest hosted systems on the hardest reasoning. Which matters more is your call, and we will tell you honestly where that line falls for your workload rather than selling you whichever answer suits us.
What protects it, everywhere it runs
Encryption
Credentials and secret-shaped fields carry authenticated encryption above disk and storage encryption. All traffic uses TLS. On the desktop, services bind to loopback only, so there is no network-exposed surface at all.
Keys you hold
Self-hosted and on-premise deployments keep the master key in your vault. We hold no copy. Rotation is supported and custody stays with you.
Single sign-on
SAML 2.0 and OIDC against your identity provider, short-lived signed sessions, and device-scoped tokens for desktop clients that can be revoked centrally when a laptop goes missing.
Immutable audit
The same append-only trail that records every recommendation and approval also records logins, source connections, exports, admin actions and device events.
Scoped access
Roles govern who connects sources, asks questions, approves actions and administers the brain. Companies are isolated from one another at every layer.
No phone-home
The offline edition is activated by a signed licence file delivered out of band and verified locally. There is no licence-server call, ever, so a disconnected deployment runs indefinitely with zero outbound connectivity.
Where we stand on certification
We would rather be straight with you than imply more than we hold. We do not currently carry SOC 2 or ISO 27001 certification. What we offer instead is an architecture that removes the need to trust us with your data at all: run it inside your own boundary and there is no third party in the path to certify. If your procurement requires certification from every vendor regardless of architecture, tell us early and we will say plainly whether we are a fit.
Tell us your constraints. We will tell you what fits.
Residency, air-gap, an existing model endpoint, a mixed field and office team, or a security review that needs answering. Bring the hard version of the question.