Identity + access
Named accounts, role-based access, least-privilege tool permissions, administrator separation where practical, and periodic access review.
Security + trust
DGM begins with a data-flow map, access matrix, vendor schedule, and risk decisions. “Local-first” is used precisely: approved local workloads can stay on client-controlled equipment, while every enabled external path is documented.
Data-flow disclosure
Actual data location depends on the approved workflow. The final data-flow map identifies sources, processors, destinations, retention, and owners.
| Layer | Reference behavior | When data may leave | Control record |
|---|---|---|---|
| Local model runtime | Inference runs on the client’s Mac Studio environment | Only if an approved fallback or external model is invoked | Model + route schedule |
| Business knowledge | Approved collections are stored and indexed in the client environment | When content is intentionally sent to a named connector or API | Collection + permission register |
| Hermes agent | Instructions, tools, and policies run within the configured orchestration environment | When an approved tool calls a third-party service | Tool + action matrix |
| CRM / SaaS | Records remain in the client’s selected platform | The platform and its subprocessors handle data under their own terms | Vendor + license schedule |
| Logs / backups | Stored in the approved local or client-controlled destination | If a hosted monitoring or backup service is separately approved | Retention + recovery plan |
Package-specific control set
Exact products and settings are confirmed in the design package. Security requirements beyond the selected package must be added to scope.
Named accounts, role-based access, least-privilege tool permissions, administrator separation where practical, and periodic access review.
Credentials are not embedded in site content or training data. Connectors use approved accounts and documented credential handling.
High-impact actions such as publishing, sending, deleting, changing records, or committing spend use human review where specified.
Agreed system events, workflow runs, errors, and administrative changes are retained for the defined period and reviewed through support procedures.
Approved configuration and data backups, documented destinations, retention targets, and at least one restore verification during implementation.
Material changes to models, instructions, tools, permissions, or workflow logic are tested and recorded before production release.
AI-specific risk
The platform is designed for assistive and controlled operational use. It is not marketed as error-free or safe for every decision.
Representative prompts, expected behavior, prohibited behavior, tool-use cases, and exception paths are tested against an agreed evaluation set.
Retrieval can provide source context for designated workflows, but source retrieval does not guarantee that every generated statement is correct.
Low-confidence, sensitive, exceptional, or high-impact cases can be routed to responsible staff under the approved workflow design.
Vendor + license discipline
The software schedule records the vendor, product, purpose, account owner, license term, allowance, renewal responsibility, usage limits, data role, and known dependency for each approved service.
Public website safeguards
The public inquiry system is intentionally separated from client production environments and is designed for non-confidential contact and scheduling data only.
Form submissions use encrypted transport, same-origin checks, server-side field validation, body-size limits, a spam trap, request throttling, and no-store API responses.
Content security, framing, referrer, content-type, permissions, and transport headers reduce unnecessary browser capabilities and common delivery risks.
Security reports can be sent to Yeshua@kairossystems.ai. A machine-readable contact is published at /.well-known/security.txt.
DGM can document the deployed controls and provide evidence described in the SOW. Whether the client’s use meets a particular law, regulation, contract, framework, or certification requirement depends on the client’s facts and qualified review.
Local processing can reduce certain external data transfers. It does not eliminate risks from users, networks, malware, physical access, backups, configuration errors, connectors, or third-party services.
Availability depends on client facilities, power, networks, hardware, maintenance, software, and external vendors. Required uptime, recovery time, or recovery point commitments must be explicitly engineered and contracted.
AI-assisted output requires review appropriate to its use. The client remains responsible for decisions, communications, approvals, legal obligations, and actions taken through its accounts.
Security discovery
Identify sensitive data, residency requirements, prohibited tools, identity standards, logging needs, and recovery expectations before the architecture is approved.