Security
Local-first is a security posture before it is a feature. The less data that moves, the less there is to attack.
A smaller attack surface
When work runs on your own hardware, prompts and data are not sitting on someone else’s server waiting to leak. The default path keeps the sensitive material on the device, which removes a whole class of risk rather than mitigating it.
How keys are handled
In hosted Soriku Cloud, your remote-provider keys live encrypted in your workspace. They are decrypted at request time, used, and dropped. There is no long-term server-side storage of your credentials.
European infrastructure
Atypisch is registered in the Netherlands and Soriku Cloud runs on European infrastructure. Mistral is the recommended remote primary, so the default path stays inside the EU.
Audit trail
Team workspaces keep an audit log of who ran what, when, against which model. The detail on what is logged and how long it is kept is in the audit log docs.
Responsible disclosure
Found something? Email security@atypisch.nl. Tell us what you found and how to reproduce it, give us reasonable time to fix it, and do not exfiltrate data or degrade the service. We will credit you if you want.