Under the
hood.
The homepage presents how Neural ICE is used. This page explains to your security team how the productisation layer and agentic harness are secured: model provenance, platform safeguards, AI-layer defences and the detailed architecture of each module. These capabilities form the architecture delivered with every AC:1 appliance.
Air-gap compatibility is a precise claim. Here are the flows that may leave the AI device.
The terms "sovereign" and "air gap" are often used without a precise definition. We document the complete traffic matrix instead: every exchange, its destination and its rule. Nothing is implicit.
In an air-gapped environment, this communication is disabled and signed updates are delivered on integrity-verified offline media.
This is the commitment we want to be judged by: sovereignty is not a slogan but a traffic matrix. If a flow is not documented in this table, it must not exist.
Secure by design, before any prompt is typed.
Security operates at two complementary levels. The AI device protects the machine, storage, access and communications against conventional cyber risks. Controls specific to AI are added to this foundation and detailed in the next section. Every update is signed and its authenticity is verified before installation.
// platform controls · included on every delivered AI device
Key industry risks, addressed one by one.
The AI layer has safeguards aligned with the OWASP Top 10 for LLM applications. The architecture reduces some risks directly; protections against the others are improved continuously.
A decentralised fleet reduces the concentration risk created by a central repository of customer content. Each organisation still needs its own backup, recovery and availability plan; local architecture changes the risk profile rather than eliminating risk.
Eight modules, all continuously improved.
// hover or tap a module to read why it matters
NVIDIA DGX Spark
The first hardware platform validated for Neural ICE AC:1, with performance suited to AI workloads in a desktop-sized system.
No datacenter required: it plugs in like a workstation and provides dedicated compute resources to one professional. The software architecture also supports validated x86-64 workstations with NVIDIA GPUs.
ICE-CoreOS
An immutable, signed, container-native OS with a retained local rollback path, open and public on GitHub.
The software foundation is read-only and verified through the boot chain. Atomic OS updates retain the previous deployment for local recovery. The public code also allows its behaviour to be inspected.
Right-sized open-weight intelligence
A supported catalogue of SLM and larger open-weight models, each validated to run entirely on the AI device.
You choose the model from the supported catalogue. The active model and version remain identifiable, local and replaceable rather than hidden behind an opaque hosted endpoint.
Sealed by design
Hardware-protected storage, a licence policy limited to one registered AI device and no service intended for exposure on the public Internet.
Keys are generated and remain inside the AI device. The licence policy is limited to one registered machine, while client access is designed for authenticated local connections rather than public Internet exposure. A tamper-evident audit trail records relevant events and lets you verify its history.
AC:1 · multimodal agentic production
Text, images, page structure and business data become source-grounded analyses, KPIs and editable deliverables through a bounded agentic workflow.
Specialised agents can divide and consolidate multi-step work. Deterministic tools handle calculations and data transformations, while source spans and lineage keep the result inspectable.
Fits what you already use
A native client for Windows, macOS and Linux, Nomad Access and optional Google Workspace and Microsoft 365 mail-and-calendar connectors.
Local mode remains the default. Nomad Access connects authorised devices remotely without exposing the AI device on the Internet. When you explicitly enable a connector, AC:1 can inspect mailbox results, prepare email drafts and create calendar events under your account, while its complete knowledge base stays on the AI device.
Practical portability
Your generated documents, knowledge-base archives, configurations and adapted models can be exported in documented, portable formats.
You own the hardware, the operating-system core is open, and your generated documents, knowledge-base archives, configurations and adapted models can be recovered in documented, portable formats.
Compliance supported by the architecture
Neural ICE is designed to support GDPR, Swiss FADP and AI Act requirements and FINMA-regulated environments. Its audit trail can contribute evidence to an ISO/IEC 42001 management system.
Rules for certain Annex III high-risk AI systems apply from 2 December 2027. Prepare to your own timetable rather than in a rush.
// all modules are maintained through the signed release channel
A production system that understands, analyses and delivers.
AC:1 surrounds the model you choose with multimodal retrieval, structured understanding, deterministic data tools and a bounded multi-agent orchestrator. It can turn a mixed body of documents, images and tables into a calculated, source-grounded deliverable. The model reasons and drafts; tools retrieve, extract, calculate, render and verify.
Retrieves meaning from text and images
Indexes text passages and page-level visual representations from PDFs, scans and image files. Hybrid retrieval can return the relevant passage, page, table or visual element with its document context.
Extracts structured facts with provenance
Schema-guided extraction identifies entities and typed fields across many documents, retains the supporting character span and publishes reusable datasets with lineage traces and quality gates.
Computes results instead of inventing figures
Bounded analytical tools query, join, clean, rank and aggregate tabular sources. KPIs, validations and chart-ready datasets remain reproducible and linked to their inputs.
Creates editable files, not just chat
AC:1 produces PDF and editable Word reports, CSV or Excel workbooks, PNG/SVG/PDF charts and PDF, PowerPoint or self-contained HTML presentations on the AI device.
Works with Google Workspace and Microsoft 365
Optional connectors support mailbox searches, human-reviewed email drafts and calendar-event creation. They are disabled by default and only exchange the data needed for the requested action.
About one million decisions, served locally
The Legal Assistant searches full-text Swiss decisions in French, German and Italian and retrieves the complete source before quoting. The AI device packages OpenCaseLaw's CC0 corpus and MIT-licensed software ↗; runtime search is fully local, with a mirrored update and sovereign rebuild path.
Role-specific assistants for CISOs, DPOs and CIOs extend the same AC:1 foundation with dedicated tools, knowledge and governance policies.
You wouldn't share a work phone. Why share an AI?
The tools that hold your thinking have always been personal. Yet AI, the one tool that reads your documents, drafts and incomplete reasoning, is often pooled across an entire organisation. Neural ICE takes the opposite stance: individual AI, one AI device per professional. A personal work assistant, not a shared corporate chatbot.
One person, one AI device
Dedicated hardware, models and memory. Your processing is not slowed by another user's workload.
Shaped by your context
Your private knowledge base, documents and way of working support deep personalisation. A shared service must remain generic; a dedicated AI device can adapt much more closely to your context.
Separated by hardware
Two users' data is never processed on the same hardware. Isolation rests on a dedicated AI device, not only on a software policy.
One AI device per professional costs more than a shared account. That premium funds dedicated hardware, stronger isolation and deeper personalisation. Strategic autonomy also depends on a hardware choice.