Security and deployment

Run the audit where your data lives.

Use the bundled local model and deterministic checks for local operation. Retain findings on your own storage and verify package integrity offline. Optional remote model roles send the required material directly to the providers you select.

01

Your source material is read—not moved or rewritten

VeriTrooper reads the files and folders you select so it can index, test, and cite them. It does not edit, rename, relocate, overwrite, or delete the source files.

  • The original path remains the source of record
  • Indexes, logs, reports, and evidence packages are created as separate output
  • Duplicate, conflict, and correction findings require a human decision
  • Legal-hold, retention, and records-management controls remain intact until your organization deliberately acts
02

New audit records are written locally

The product must create working and evidentiary records, but those are new artifacts—not changes to the source corpus.

  • Local indexes and temporary processing material
  • Watchtower capture records when you use its local capture service
  • Reports, findings, configuration snapshots, and run logs
  • Machine-readable integration exports
  • Signed manifests, verification material, and human signoff history
  • All output locations remain on customer-controlled storage
03

Run the audit where your data lives

Use the bundled local model and deterministic checks for local operation. Retain findings on your own storage and verify package integrity offline. Optional remote model roles send the required material directly to the providers you select. All active endpoints must be local for a fully local run; the package records the configured boundary.

  • No claim, question, passage, or result leaves the host in a fully local run
  • SitRep keeps active analysis roles local unless an operator turns air-gapped mode off
  • Watchtower passively audits the local conversation record without calling the deployed assistant by default
  • Scout supports local diagnostic review and deterministic verification; the record identifies the roles used
04

The only network traffic is traffic you deliberately configure

VeriTrooper does not route audit data through VeriTrooper LLC. When an operator selects a cloud model or remote endpoint, the application communicates directly with that customer-selected service using the customer's connection.

  • Auditing a cloud model requires sending it the questions and relevant passages it must answer
  • Selecting remote diagnostic or verification roles sends the material required by those roles to the selected providers
  • Pointing every role and the model under test at local endpoints keeps the audit local end to end
  • Provider handling remains governed by the customer's agreement and configuration with that provider
05

Credentials stay in the customer deployment

API keys, endpoint URLs, and tokens are entered into the locally deployed Console and used to reach the connections the customer configures. They are not sent to VeriTrooper LLC.

  • Air-gapped runs require no provider credential
  • Keys are masked in the interface unless an operator deliberately reveals them
  • Customers control the host account, filesystem permissions, network policy, key rotation, and endpoint authorization
06

The evidence records the boundary actually used

The package records the run mode, selected roles, configuration, source scope, and relevant connection posture. A reviewer does not have to rely solely on a verbal claim that the run was local.

  • Isolation Posture describes the recorded data-handling configuration
  • Canonical records preserve the settings used for the run
  • Remote selections and air-gapped operation are distinguishable in the evidence
  • A package never claims a network timestamp when an air-gapped run could not obtain one
07

Successfully completed, seal-eligible packages are tamper-evident

A package that passes consistency and sealing gates binds its listed artifacts to a signed manifest and includes a portable checker that can identify files that were changed, removed, or added.

  • The detached signature binds the manifest
  • The checker requires no VeriTrooper installation, Python runtime, or network connection
  • The signer fingerprint must be compared through a separately supplied trusted channel
  • Human signoff is bound only when a current approved signoff record exists
  • An RFC 3161 timestamp is included only when enabled and successfully obtained
08

Workstation requirements

VeriTrooper can run on a standard modern Windows workstation. For the best experience with bundled local AI analysis, use the recommended configuration.

  • Minimum memory: 16 GB RAM
  • Recommended memory: 32 GB RAM
  • Recommended graphics memory: 8 GB VRAM
  • Windows evaluation installation: at least 10 GB free, plus space for audit data
  • Bundled local model size: approximately 4.92 GB
09

Controls that remain with the customer

Local deployment preserves customer control; it does not replace the customer's security program.

  • Host hardening, user access, endpoint protection, backup, and physical security
  • Provider credentials, network allowlists, firewall policy, and key rotation
  • Approved data scope, retention, legal hold, archival, and disposal
  • Review of referrals, findings, overrides, and final signoff
  • Professional interpretation of results and any legal or conformity determination
Next step

Test the claim on your own system.

Discuss an assessment