Trust

Security

Local-first is a security posture before it is a feature. The less data that moves, the less there is to attack.

A smaller attack surface

When work runs on your own hardware, prompts and data are not sitting on someone else’s server waiting to leak. The default path keeps the sensitive material on the device, which removes a whole class of risk rather than mitigating it.

How keys are handled

In hosted Soriku Cloud, your remote-provider keys live encrypted in your workspace. They are decrypted at request time, used, and dropped. There is no long-term server-side storage of your credentials.

European infrastructure

Atypisch is registered in the Netherlands and Soriku Cloud runs on European infrastructure. Mistral is the recommended remote primary, so the default path stays inside the EU.

Audit trail

Team workspaces keep an audit log of who ran what, when, against which model. The detail on what is logged and how long it is kept is in the audit log docs.

Responsible disclosure

Found something? Email security@atypisch.nl. Tell us what you found and how to reproduce it, give us reasonable time to fix it, and do not exfiltrate data or degrade the service. We will credit you if you want.