Security & Privacy

Built for privacy. Designed for trust. Auditable by default.

Core Security Principles

Local-First Data Control

All LLM prompts and client data stay on your device. Nothing leaves your environment unless you explicitly allow it.

Zero Telemetry by Default

No cloud calls, no tracking, no analytics—unless you opt in. We don't know what you're doing with Menz0OS, and that's by design.

Role-Based Access Control (RBAC)

Four roles (Admin, Manager, Technician, Client) with scoped permissions. Every action is logged with user, timestamp, and input/output hashes.

Consent-Gated Remote Access

All remote support requires UI confirmation. Sessions are time-bound with IP and action logging. Auto-expiry after session ends.

Security Features

Local LLMs (Ollama) - All AI prompts run on-device

Zero telemetry by default - No cloud calls unless opted in

RBAC with 4 roles - Admin, Manager, Technician, Client

Full audit trails - JSON logs per user/module

Consent-gated remote access - Time-bound sessions with IP/action logging

Sandboxed plugin execution - Scoped permissions, isolated processes

GDPR/CCPA-ready - Local-only data by default

Offline-first architecture - Full feature parity without internet

Encrypted backups - Admin-controlled recovery

Regulatory Compliance

GDPR

Compliant

Local-only data by default. No third-party processors without explicit consent.

CCPA

Compliant

No tracking, no data sale, full data control. Opt-in for all cloud features.

HIPAA

Advisory

Secure audit trails and no cloud dependency support HIPAA requirements.

Security Architecture

ComponentSecurity Policy
LLM PromptsLocal-only (Ollama)
Client DataStored on-device
File UploadsScoped, hashed, auditable
Plugin AccessScoped + logged
FleetCommandEncrypted opt-in metrics only

Questions About Security?

We're happy to discuss our security architecture in detail.