Security / 6 August 2026 / 7 min

Local perimeter: when data must not leave the computer

Confidential legal materials, commercial negotiations, and sensitive meeting recordings are common reasons to choose a controlled local deployment.

Short answer: Local deployment is designed for tasks whose data must remain on customer-controlled infrastructure. That boundary requires a configuration with no external integrations; data flows, access controls, and compliance with Federal Law No. 152-FZ must be reviewed before deployment.

Three environments: cloud, team, and local

The agentseffect.com catalog describes three processing environments: cloud, team and local. The perimeter is chosen before launch — together with the sources, the allowed actions and the retention period. In a local configuration with no external integrations, processing and storage run on customer-controlled infrastructure and the data remains within the approved environment.

What runs locally

The catalog offers a local configuration for three solutions:

  • Super Oracle. Supports a local configuration with no external integrations: processing runs on customer-controlled hardware, and environment requirements are confirmed before launch.
  • The local meeting scribe. In a configuration without external integrations, it transcribes meetings without sending the recording to an external service; hardware requirements are confirmed during implementation. Base configuration: Windows 10/11, 16 GB of RAM, an NVIDIA video card with 6 GB or more.
  • The requirements analyst. Supports local deployment: in a configuration with no external integrations, materials from discovery through the specification remain within the approved environment.

When local deployment is appropriate

Three common situations are confidential legal or medical materials, commercial negotiations and internal meetings, and customer or regulatory requirements that restrict transfer to external services.

A local installation does not by itself ensure that no data leaves the system. The boundary must be verified through a configuration with no external integrations, access controls, logs, and network testing. Duties under Federal Law No. 152-FZ still require review for the specific processing arrangement.

The solution can be deployed locally or in the cloud, depending on the approved configuration.

The cost of local deployment

A complete assessment must also account for the costs. The local perimeter requires your own hardware and its maintenance. Performance is limited by your machine: hence the requirements for the RAM and the video card. Depending on the configuration, updates may require manual installation. These costs reflect the choice to keep processing and storage on infrastructure controlled by the customer.

What to check before choosing a perimeter

The checklist from the trust model of the project: which sources are connected (least privilege — each source separately), who confirms sensitive actions (explicit consent with the explanation of the consequence), how the launch journal is kept and how the materials are deleted after the work. The environment is defined not only by where processing runs, but also by access controls, logging, and material deletion.

Read also: How not to give the agent extra data: read-only and access boundaries · Synthetic demo: why an honest demonstration beats a "live case"

Questions and answers

Does a local agent need the internet?

Some solutions can perform their core functions without internet access when deployed locally with no external integrations. Update and licensing requirements are confirmed before deployment.

What about Federal Law No. 152-FZ?

Local processing can reduce data transfers, but it does not remove the operator's duties. The customer's specialists must review the specific data flow, safeguards, and contractual terms.

Can we move to the cloud perimeter later?

The choice of perimeter is fixed before launch, but the permissions and the processing perimeter are passport fields that can be revised by an explicit decision with the update of the passport and the journal.

Which products run locally?

Local configurations are available for Super Oracle, the local meeting scribe, and the specification preparation system; environment requirements are confirmed before launch.

What is needed for Super Oracle?

In a configuration with no external integrations, processing runs within the approved local environment. Hardware requirements are confirmed before launch.

Is the local perimeter suitable for attorney privilege?

Local processing shrinks the disclosure perimeter; the attorney or commercial privilege regime is agreed before launch.

What does the protection perimeter include?

The sources, the allowed actions, the processing perimeter and the retention period are set before launch.

How can the local data boundary be verified?

Review the configuration documentation, logs, and network traffic. In the approved local configuration, the meeting scribe does not send recordings to an external service.

First step

Choose a ready-made solution or describe your process.

Pick one of the twelve agents and subagents, or fill in the questionnaire for custom development.

Search agentseffect.com

Quick links