v2.3.0 Local-first AI Enterprise governance
Local AI for confidential documents — Q&A, reports, and diagrams without sending data to the cloud.
Marketing presentation · June 2026
| Pain | Business impact |
|---|---|
| Data sovereignty | Client IP and regulated data cannot leave the perimeter |
| Unpredictable cost | Per-token API bills grow with every analyst |
| Hallucination & trust | Generic chat is not grounded in your policies |
| Vendor lock-in | Outages and policy changes block critical work |
Teams resort to manual PDF search or risky use of public ChatGPT.
| Layer | Highlights |
|---|---|
| LLM | LM Studio (primary); failover URL; streaming; JSON reports; model routing |
| RAG | ChromaDB + local embeddings; token-aware chunking; anti-hallucination prompts |
| Documents | python-docx / python-pptx; diagram CLI render to PNG/SVG |
| Security | API key, OIDC, RBAC, SSRF-safe scrape, air-gap defaults |
| Governance | OWASP LLM, NIST AI RMF, EU AI Act, gap assessment, SLHP scheduler, SBOM/AIBOM |
GET /capabilities · GET /governance/assurance/summary
| ID | Scenario | Outcome |
|---|---|---|
| UC-01 | Internal policy Q&A | Sourced answers for audit & ops |
| UC-02 | Compliance / gap report | DOCX/PPTX in minutes |
| UC-03 | Controlled web ingest | Expand KB when policy allows |
| UC-04 | Architecture diagrams | PNG/SVG deliverables |
| UC-05 | General chat | Drafting without KB |
| UC-06 | GRC evidence pack | Framework crosswalk + trust index |
| UC-09 | Regulatory / law Q&A | Cited official texts in KB |
| UC-10 | Security gap & Red Team | Gap API + exercise program |
Illustrative pilot-style scenarios — substitute your customer logos and metrics after deployment.
| Scenario | Challenge | Result |
|---|---|---|
| Consulting firm | ChatGPT used on client docs | Zero egress; faster DOCX summaries; audit trail |
| Financial compliance | 200+ policy PDFs | Hours → minutes to answer; explicit “no context” |
| Air-gapped agency | No cloud AI allowed | Full offline workflow after model install |
| OT / industrial | Ungoverned AI tools | 98% unified assurance; OT deploy templates |
| Driver | Cloud AI | Sovereign |
|---|---|---|
| Inference | Per-token / seat | Fixed hardware + open models |
| Data egress | Implicit | None |
| Integration | Multiple tools | Single workbench + GRC APIs |
Avoid $6k–$24k+ in team cloud-AI subscriptions* · Amortized hardware $2k–$5k
*Illustrative; adjust for your market. See PRESENTATION.md for full TCO table.
| vs | You win when… |
|---|---|
| Cloud AI (ChatGPT, Claude) | Sovereignty, predictable cost, native RAG + reports matter most |
| DIY RAG (LangChain) | You need productized UI, audit, and GRC in days not months |
| Suite AI (Copilot, Duet) | M365/Workspace lock-in is unacceptable; air-gap required |
| Vertical compliance SaaS | You need flexible corpus + AI deliverables + framework crosswalk |
Frontier cloud models still lead on complex reasoning; Sovereign leads on control and TCO.
| Edition | Target |
|---|---|
| Community | Pilot / individual |
| Professional | Small teams · Docker |
| Enterprise | Regulated · SSO · SLA |
demo/sample_policy.txt/health, audit log, /governance/assurance/summary