The commitments SEAT is engineered against
This note is written for the people a family asks to look closely. It states the architectural commitments in plain terms. Full specifications, the threat model, and the contractual form of each commitment are provided under NDA during establishment.
Commitments
-
01
Residence. All computation, storage, and inference occur on hardware the family owns, inside the household perimeter. Core function has no cloud dependency: the intelligence works when the internet does not.
-
02
No external visibility. No telemetry leaves the property. There is no standing remote access — not for us, not for any vendor. What we cannot reach, we cannot lose, sell, or be compelled to produce.
-
03
Three registers of ownership. Personal, family, and house memory are held under separate ownership and transfer rules. When a property is sold, its register is separated, settled, and conveyed; the family's register travels with the family.
-
04
Scoped access. Each member holds their own key. Staff, advisors, and the family office see precisely what they are granted, and nothing more. Every disclosure is recorded: who asked, what was shown, when.
-
05
Succession by instrument. Permission transfer is defined in writing at establishment — coming of age, incapacity, death, divorce, sale. The intelligence follows the family's instruments, not its accidents.
-
06
Model isolation. Models run locally. No third party trains on the family's data — ever. Updates arrive as signed artifacts and are installed only with the household's consent.
-
07
Network posture. Egress is denied by default and opened by exception, per purpose, with a record. The household operates through grid and internet outages on its own stored energy.
-
08
Auditability. An append-only audit trail is readable by the principal and, on the principal's grant, by counsel. The system's account of itself is not editable — by anyone.
The perimeter
One drawing carries the essential fact: nothing of consequence crosses the outer line.
What we can see, and cannot
We cannot see
- Conversations and recordings
- Documents and correspondence
- Presence, movement, and routine
- The contents of any memory register
- What the intelligence has learned or concluded
- The audit trail itself
We can receive — only if the family exports it
- A device-health summary, signed and reviewed by the household before release
- A receipt confirming an update was installed
- Nothing else
The asymmetry is deliberate. A promise not to look can be broken; an architecture that cannot look, cannot.
Service and lifecycle
Installation is performed by a small, named crew. Service sessions are scheduled in advance, supervised by the household, and logged in the audit trail. Storage media never leave the property: at end of life, drives are destroyed on site, witnessed. Hardware is refreshed on a defined cycle; the family's registers carry forward, the old machines carry nothing out.
SEAT is established against these commitments, and they are given contractual form at establishment. Counsel is invited to hold us to them.