Local processing
When the configured default model endpoint is local, prompts, chat history, project data, skills, agent metadata, usage records, and credentials stay inside your own deployment. The operator controls access, retention, and which services are connected.
Credentials are encrypted at rest with AES-256-GCM, authentication runs on your own database or an OAuth provider you configure, and privileged actions are written to the audit log.
Explicit external connectors
External models, web search, OAuth providers, and MCP servers receive data only when you enable the connection and use it. A default chat route configured to a local endpoint stays inside your deployment, and an outbound feature does nothing until you have configured it.
ChatGPT subscription OAuth is optional, unofficial, and dependent on the provider's policy. NotebookLM grounding uses a Google session cookie that you supply.
Desktop local-work bridge
A connected folder is handled on the device through scoped bridge controls. The full local path is not sent to the server merely so the desktop menu can display it, and file access is confined to the folder you chose.
OpenMake