What the Outpost discloses, what stays on your machine, and what we can do
The Outpost runs on your network; source files and the search index live on your
machine. You decide per folder on the Outpost what meinGPT gets to see in order
to answer a question — and that setting is what this page is about.
Attention
On-premise does not mean "nothing leaves". It means: only what you
release. An answer without the passage it rests on would be no answer, so at
minimum the matching passage travels to meinGPT with every question. How much
more is up to you.
Every shared Outpost folder has a release level. It decides what leaves the
machine when someone asks a question.
Level
What travels to meinGPT
Text only
The matching passages, the file name and the complete text of the relevant documents. The default.
Original files
Everything from “Text only” plus the file itself. Needed when people should verify an answer against the original, or reuse a template.
A lower level that released only individual passages is gone: whoever may read
one passage can ask a second question for the next one and assemble the document
that way. It cost answer quality and protected nothing. Existing data pools
still set to it keep working unchanged.
It is set on the Outpost, per folder — in the program on the machine, under
Shares → open the folder. Not in the web console.
Until recently it was the other way round: a dropdown in the platform, one level
for every folder on a machine, operated by someone who cannot see the disk.
Whoever decides that \\fileserver\HR should be searchable is the same person
who knows whether its files may leave the building — and they are at the
machine, not in a browser.
The folder reports its level with every folder report, and meinGPT enforces it:
requests asking for more than the folder releases are refused before anything is
read.
What an update does not change
A folder bound before this change reports no level. It is treated as text
only — the careful side. No folder starts releasing files because of an
update.
The Outpost opens the connection itself. No inbound port, no firewall rule,
no service exposed to the internet.
A key per organization
The tunnel is signed with a key that belongs to your organization alone —
not with a shared secret.
Technically it is an outbound, TLS-encrypted WebSocket connection to the meinGPT
Bridge — not a VPN. Your network team has nothing to open; outbound HTTPS is
enough. Corporate proxies and private root certificates are supported, and the
setup assistant checks them.
The platform cannot set any of these. They exist only on the device, by design:
if the cloud could add a folder, the cloud could read anything on that machine.
Which folders are shared. This is the actual boundary.
Which local services are reachable, and with which credentials. The
password is never transmitted to meinGPT.
The root certificate for your TLS inspection.
Where embeddings go — the address of the model that turns your documents
into vectors.
The Outpost updates itself from storage we operate, signed with a key we hold.
That carries an uncomfortable but honest limitation: we could ship a version
that behaves differently from the one described here. Everything on this page
is, today, a commitment rather than a technical proof.
To close that gap, turn auto-update off and pin a version you have reviewed. The
price is that you apply updates yourself — in exchange, nothing rests on our
restraint any more.
In the web console ("Unpair device"): the secret is rotated and
outstanding pairing codes are deleted. The right move when a machine is
stolen, decommissioned, or no longer reachable.
On the device ("Unpair this device"): the same — the Outpost revokes
itself at meinGPT before clearing anything locally. If meinGPT cannot be
reached, the app says so rather than reporting success, and offers
"Disconnect locally" instead — access then stays valid at meinGPT and has
to be revoked in the web console.
Both are recorded in your organization's audit log.