Security and deployment

Keep the audit inside the approved boundary.

VeriTrooper is locally deployed software. VeriTrooper LLC operates no hosted audit service and cannot see your source material, prompts, answers, credentials, or results.

01

Your source material is read—not moved or rewritten

VeriTrooper reads the files and folders you select so it can index, test, and cite them. It does not edit, rename, relocate, overwrite, or delete the source files.

  • The original path remains the source of record
  • Organize Your Data produces recommendations and an organization record; it never moves or deletes files
  • Duplicate, conflict, and correction findings require a human decision
  • Legal-hold, retention, and records-management controls remain intact until your organization deliberately acts
02

New audit records are written locally

The product must create working and evidentiary records, but those are new artifacts—not changes to the source corpus.

  • Local indexes and temporary processing material
  • Watchtower capture records when you use its local capture service
  • Reports, findings, configuration snapshots, and run logs
  • Machine-readable integration exports
  • Signed manifests, verification material, and human signoff history
  • All output locations remain on customer-controlled storage
03

Air-gapped operation is the default

Out of the box, invoked model roles run on the bundled local model and code-only roles make no model call. No provider key is required, and a computer that has never been online can complete an audit and produce a sealed evidence package.

  • No claim, question, passage, or result leaves the host in a fully local run
  • SitRep keeps active analysis roles local unless an operator turns air-gapped mode off
  • Watchtower passively audits the local conversation record without calling the deployed assistant by default
  • Scout's diagnostic reviewer is local and its default independent verifier is deterministic code
04

The only network traffic is traffic you deliberately configure

VeriTrooper does not route audit data through VeriTrooper LLC. When an operator selects a cloud model or remote endpoint, the application communicates directly with that customer-selected service using the customer's connection.

  • Auditing a cloud model requires sending it the questions and relevant passages it must answer
  • Selecting remote diagnostic or verification roles sends the material required by those roles to the selected providers
  • Pointing every role and the model under test at local endpoints keeps the audit local end to end
  • Provider handling remains governed by the customer's agreement and configuration with that provider
05

Credentials stay in the customer deployment

API keys, endpoint URLs, and tokens are entered into the locally deployed Console and used to reach the connections the customer configures. They are not sent to VeriTrooper LLC.

  • Air-gapped runs require no provider credential
  • Keys are masked in the interface unless an operator deliberately reveals them
  • Customers control the host account, filesystem permissions, network policy, key rotation, and endpoint authorization
06

The evidence records the boundary actually used

The package records the run mode, selected roles, configuration, source scope, and relevant connection posture. A reviewer does not have to rely solely on a verbal claim that the run was local.

  • Isolation Posture describes the recorded data-handling configuration
  • Canonical records preserve the settings used for the run
  • Remote selections and air-gapped operation are distinguishable in the evidence
  • A package never claims a network timestamp when an air-gapped run could not obtain one
07

Completed packages are tamper-evident

Seal-eligible packages bind their listed artifacts to a signed manifest and include a portable checker that can identify files that were changed, removed, or added.

  • The detached signature binds the manifest
  • The checker requires no VeriTrooper installation, Python runtime, or network connection
  • The signer fingerprint can be compared through a separately supplied trusted channel
  • Human signoff is bound to the reviewed result set
  • An RFC 3161 timestamp is included only when enabled and successfully obtained
08

Workstation requirements

VeriTrooper can run on a standard modern Windows workstation. For the best experience with bundled local AI analysis, use the recommended configuration.

  • Minimum memory: 16 GB RAM
  • Recommended memory: 32 GB RAM
  • Recommended graphics memory: 8 GB VRAM
  • Recommended available storage: 8 GB
  • Bundled local model size: approximately 4.92 GB
09

Controls that remain with the customer

Local deployment preserves customer control; it does not replace the customer's security program.

  • Host hardening, user access, endpoint protection, backup, and physical security
  • Provider credentials, network allowlists, firewall policy, and key rotation
  • Approved data scope, retention, legal hold, archival, and disposal
  • Review of referrals, findings, overrides, and final signoff
  • Professional interpretation of results and any legal or conformity determination
Next step

Test the claim on your own system.

Plan a guided pilot