Making files usable that must not leave your building — what an Outpost is, what you manage here, and what happens on the machine.
An Outpost is an application with a graphical interface that you install on a machine in your network — for Windows, macOS (Apple Silicon) and Linux. You point it at folders, and it reads the documents and builds a search index; both stay on that machine, and your files are not copied to the cloud.
Services are a separate preview. Databases in your own network and local MCP
servers can only be connected in workspaces for which we have explicitly
enabled the controlled services preview. If the Outpost only shows folders,
that is the expected general early-access scope.
You only need an Outpost when files or systems must not leave the building. Every other data source is connected directly under Settings → Data sources, with no hardware of your own.
Early Access — free to try
The Outpost is in Early Access. It is usable day to day and we ship
quickly — expect frequent updates, and expect individual screens to keep
changing. Trying it costs nothing: 100 documents are free — a preview, not
a plan. One service is included only when the separate services preview is
enabled for your workspace. Details under Free preview.
It is a complete rebuild of the former DataVault. The old path ran on Docker: effortful to set up, recurringly troublesome in operation — updates nobody applied, containers that did not come back up after a restart — and dependent on operations knowledge that a mid-sized IT team does not have going spare. Those teams were exactly who it was for. So instead of patching it further, we rebuilt it: as an application that installs, pairs and updates itself. We no longer publish Docker images of the Outpost — if you still run such an installation, it moves over, and your data is re-indexed in the process. Get in touch at enterprise@meingpt.com and we will set up the new Outpost together with you. Moving to the new Outpost describes what happens and why.
On-premise does not mean nothing leaves
Every answer takes at least the matching passage out of your network —
otherwise there would be no answer. Exactly what leaves is set per document
collection via the release level. There are two, and even the lower one
releases the complete text of the documents found.
Windows 10 is the documented minimum for Electron 43.1.1↗; the shipped NSIS installer is restricted to x64 in electron-builder.yml.
macOS
macOS 12 Monterey or later, Apple Silicon
macOS 12 is the documented minimum for Electron 43.1.1↗; the shipped DMG and ZIP artifacts are restricted to arm64 in electron-builder.yml. Intel Macs are not supported.
Linux
x86-64, glibc 2.39 or later, and libstdc++ providing GLIBCXX_3.4.31
This floor is set by the bundled document-extraction module. Verified with real extraction: Ubuntu 24.04 LTS and Debian 13. Not supported: Ubuntu 22.04 LTS, Debian 12, Rocky Linux 9, and AlmaLinux 9.
The higher level includes everything from the lower one.
Level
Leaves your network
What it is for
Text only(default)
the matching paragraphs, the file name and the complete text of the documents found
The file itself stays with you.
Original files
everything from “Text only” plus the file itself
People can open the file from a citation and reuse it. For a quote template, the file is the answer.
The difference is text versus artefact, not machine versus human: once you release the text, anyone can have the assistant reproduce the content. What stays protected is the form — the layout, the signed PDF, the branded template.
A third, lower level used to release only individual passages. It is gone: whoever may read one passage can ask a second question for the next one and assemble the document that way — the level cost answer quality and protected nothing. The real boundary is whether a collection is released at all, and to whom. Existing sources still set to it keep working unchanged.
Releasing a folder releases it to everyone who may see that document
collection in meinGPT — including people who could not open it in Explorer or
on the share. NTFS, Active Directory and POSIX permissions are not
inherited. Mapping folders to teams is therefore its own decision, and one you
have to make deliberately.
When the machine is off, meinGPT keeps working. Only this Outpost's documents are unfindable for that time — people get answers without those sources, not no answers. An Outpost should still run continuously, otherwise your documents are missing at night and on weekends.
A machine always calls outward. No port is opened in your firewall; the Outpost establishes the connection itself. What it needs is outbound HTTPS to *.meingpt.com.
Revoking access disconnects a machine immediately — without its cooperation. That is the control for "the laptop is gone" or "that employee left". The processed data stays on the machine; it becomes reachable again only after being reconnected.
You can try the Outpost for free: 100 documents are included. One service is
included only when the separate services preview is enabled for your workspace.
This preview is deliberately small. It is meant to answer one question, and answer it completely: does this run here? Install it on your machine, release a folder, let it index, search in meinGPT, see the hit from your own document in a chat — 100 documents are enough for that, because whether the chain works is shown just as well by the first indexed document as by the ten-thousandth.
Once those 100 documents are indexed, the preview has done its job — you have the answer it exists to give. From there the question is no longer the technology but the scale: how many collections, how many services, how much storage. We settle that together — write to enterprise@meingpt.com or talk to your contact.
After that, each workspace has a storage allowance. It is agreed individually, so there is no single number that applies to everyone. The allowance that applies to you, and how much of it is used, is shown on the on-premise page in meinGPT. The same holds for the number of internal applications (ERP, internal API, ticket system, …) you may connect.
Both limits are enforced. The application limit at create time. The storage allowance blocks only above 110% of the number — there is headroom below that. Once exceeded, semantic search on your Outposts is blocked until there is room again or the allowance is raised. If usage cannot be determined because an Outpost is unreachable, nothing is blocked.
Data sources in meinGPT Cloud have their own separate allowance, enforced the same way. Both are guardrails rather than packages: most workspaces hold a fraction of them.
The remote terminal lets a meinGPT agent run PowerShell or system-shell commands
directly on an Outpost computer. It is off by default and needs two approvals:
the workspace beta entitlement and the local switch under Settings → Remote
access. Platform entitlement cannot activate the local switch.
Enable remote terminal only on a dedicated, restricted AI computer. The grant is
broad command access to the host; executions are recorded with actor, Outpost and
outcome in the audit log.
Computer control can view an interactive Outpost session and perform mouse or
keyboard actions. An agent may either work one step at a time with a fresh
screenshot or run a fixed action sequence after inspecting the screen. It has
its own workspace entitlement and its own local switch under Settings → Remote
access; both are off by default.
Use it only on a dedicated, restricted AI computer with an unlocked session.
macOS requires Accessibility and Screen Recording permissions, Windows requires
an interactive session, and Linux requires an X11/XWayland display. A Windows
service without a signed-in session reports the feature as unavailable.
You install the Outpost application on a machine at your site — an installer on Windows, a disk image for Apple Silicon on macOS, an AppImage on Linux — and pair it with a connection code.