All AI processing is self-hosted. No data is sent to external LLM providers unless you explicitly configure a cloud provider. The PII sanitizer auto-redacts secrets (JWT, API keys, SSH keys, emails, private IPs) from AI prompts and forces local-only routing when sensitive data is detected.
Role-based data access, configurable retention and deletable RAG chunks with a full audit trail for all system changes.