Member of NVIDIA InceptionNVIDIA Inception
Neural ICE
EN · FR · DE · IT Talk to us
Secured across the device lifecycle · AC:1 technical brief

Under the
hood.

The homepage presents how Neural ICE is used. This page explains to your security team how the productisation layer and agentic harness are secured: model provenance, platform safeguards, AI-layer defences and the detailed architecture of each module. These capabilities form the architecture delivered with every AC:1 appliance.

Local inference · air-gap deployment available ICE-CoreOS is open-core Designed for environments subject to GDPR · Swiss FADP · AI Act · NIS2
Data boundaries and flows

Air-gap compatibility is a precise claim. Here are the flows that may leave the AI device.

The terms "sovereign" and "air gap" are often used without a precise definition. We document the complete traffic matrix instead: every exchange, its destination and its rule. Nothing is implicit.

Data & AI plane · your content
Documents, the knowledge base and stored results remain on the AI device. In local mode, prompts and answers travel only between the device and your authenticated app over mutually authenticated TLS on your local network. Inference always runs on the device and continues to work when the Internet cable is unplugged.
Control plane · licence & releases
For licensing and release distribution, the AI device communicates only with the Neural ICE services required to validate its licence and receive signed updates — new capabilities and security fixes. Licence validation and activation transmit only licence information, the hardware fingerprint, device name and platform type. No health status, documents, conversations or usage data are reported.

In an air-gapped environment, this communication is disabled and signed updates are delivered on integrity-verified offline media.
Nomad Access · optional add-on
Disabled by default, Nomad Access allows only previously paired devices to reach the AI device through an end-to-end encrypted private network. Traffic uses a direct connection whenever network conditions permit; otherwise, it crosses a Neural ICE-operated relay in Switzerland or the European Union in encrypted form. Each device's mTLS certificate remains mandatory, revoking it also removes access to the private network, and no AI device service is exposed directly on the Internet. The control plane establishes and authorises the connection without access to the exchanged content. This option is disabled in an air-gapped environment.
Audit export · your SIEM, optional
An administrator can export the tamper-evident audit trail as JSON or CSV, with chain verification, or forward it directly to the organisation's SIEM. These flows stay under customer control and do not pass through Neural ICE.
Connectors · optional, under your control
If, and only if, you enable a Google Workspace or Microsoft 365 connector, the agent connects to that service on your behalf, under your credentials. It exchanges only the fields required for the action you requested, such as a mailbox query, an email draft or calendar-event details. The complete knowledge base is never transmitted. Connectors are off by default, enabled individually and revocable at any time.

This is the commitment we want to be judged by: sovereignty is not a slogan but a traffic matrix. If a flow is not documented in this table, it must not exist.

Countermeasures · platform layer

Secure by design, before any prompt is typed.

Security operates at two complementary levels. The AI device protects the machine, storage, access and communications against conventional cyber risks. Controls specific to AI are added to this foundation and detailed in the next section. Every update is signed and its authenticity is verified before installation.

// platform controls · included on every delivered AI device

Verified boot chain Immutable, signed OS · retained local rollback Hardware-bound disk encryption Mandatory access control Internal mTLS mesh No service intended for public Internet exposure Licence policy limited to one AI device Tamper-evident audit trail Air-gap capable JSON/CSV audit export for SIEM
Countermeasures · AI layer

Key industry risks, addressed one by one.

The AI layer has safeguards aligned with the OWASP Top 10 for LLM applications. The architecture reduces some risks directly; protections against the others are improved continuously.

LLM02 · Sensitive information disclosure
A dedicated AI device prevents another user from sharing your models, memory or hardware. This separation substantially reduces cross-user leakage risks, while local processing limits exposure of your content to external services.
LLM09 · Misinformation
AC:1 is designed to produce supported answers: figures are computed by deterministic tools and claims can be linked to a source you can inspect. Incorrect answers are therefore easier to identify.
LLM06 · Excessive agency
The agent uses a defined set of tools under human oversight, with a tamper-evident audit trail. It can draft freely, but the actions it can execute remain explicitly limited.
LLM03 · Supply chain
The open-core foundation is inspectable, while every selected open-weight model is identified by source and version. Signed operating-system, application and bundle artifacts are verified before they are applied.

A decentralised fleet reduces the concentration risk created by a central repository of customer content. Each organisation still needs its own backup, recovery and availability plan; local architecture changes the risk profile rather than eliminating risk.

AC:1 · module by module

Eight modules, all continuously improved.

NVIDIA DGX Spark · first platform validated by Neural ICE ICE-CoreOS is open-core · inspect it on GitHub ↗

// hover or tap a module to read why it matters

MOD·01 / Platform● included

NVIDIA DGX Spark

The first hardware platform validated for Neural ICE AC:1, with performance suited to AI workloads in a desktop-sized system.

MOD·01 / why it matters

No datacenter required: it plugs in like a workstation and provides dedicated compute resources to one professional. The software architecture also supports validated x86-64 workstations with NVIDIA GPUs.

MOD·02 / Operating system● included

ICE-CoreOS

An immutable, signed, container-native OS with a retained local rollback path, open and public on GitHub.

MOD·02 / why it matters

The software foundation is read-only and verified through the boot chain. Atomic OS updates retain the previous deployment for local recovery. The public code also allows its behaviour to be inspected.

MOD·03 / Models● included

Right-sized open-weight intelligence

A supported catalogue of SLM and larger open-weight models, each validated to run entirely on the AI device.

MOD·03 / why it matters

You choose the model from the supported catalogue. The active model and version remain identifiable, local and replaceable rather than hidden behind an opaque hosted endpoint.

MOD·04 / Security● by design

Sealed by design

Hardware-protected storage, a licence policy limited to one registered AI device and no service intended for exposure on the public Internet.

MOD·04 / why it matters

Keys are generated and remain inside the AI device. The licence policy is limited to one registered machine, while client access is designed for authenticated local connections rather than public Internet exposure. A tamper-evident audit trail records relevant events and lets you verify its history.

MOD·05 / Agentic core● included

AC:1 · multimodal agentic production

Text, images, page structure and business data become source-grounded analyses, KPIs and editable deliverables through a bounded agentic workflow.

MOD·05 / why it matters

Specialised agents can divide and consolidate multi-step work. Deterministic tools handle calculations and data transformations, while source spans and lineage keep the result inspectable.

MOD·06 / Your setup● included

Fits what you already use

A native client for Windows, macOS and Linux, Nomad Access and optional Google Workspace and Microsoft 365 mail-and-calendar connectors.

MOD·06 / why it matters

Local mode remains the default. Nomad Access connects authorised devices remotely without exposing the AI device on the Internet. When you explicitly enable a connector, AC:1 can inspect mailbox results, prepare email drafts and create calendar events under your account, while its complete knowledge base stays on the AI device.

MOD·07 / Portability● by design

Practical portability

Your generated documents, knowledge-base archives, configurations and adapted models can be exported in documented, portable formats.

MOD·07 / why it matters

You own the hardware, the operating-system core is open, and your generated documents, knowledge-base archives, configurations and adapted models can be recovered in documented, portable formats.

MOD·08 / Compliance● by design

Compliance supported by the architecture

Neural ICE is designed to support GDPR, Swiss FADP and AI Act requirements and FINMA-regulated environments. Its audit trail can contribute evidence to an ISO/IEC 42001 management system.

MOD·08 / why it matters

Rules for certain Annex III high-risk AI systems apply from 2 December 2027. Prepare to your own timetable rather than in a rush.

// all modules are maintained through the signed release channel

AC:1 · Agentic Core · included with every AI device

A production system that understands, analyses and delivers.

AC:1 surrounds the model you choose with multimodal retrieval, structured understanding, deterministic data tools and a bounded multi-agent orchestrator. It can turn a mixed body of documents, images and tables into a calculated, source-grounded deliverable. The model reasons and drafts; tools retrieve, extract, calculate, render and verify.

Multimodal RAG

Retrieves meaning from text and images

Indexes text passages and page-level visual representations from PDFs, scans and image files. Hybrid retrieval can return the relevant passage, page, table or visual element with its document context.

Grounded extraction

Extracts structured facts with provenance

Schema-guided extraction identifies entities and typed fields across many documents, retains the supporting character span and publishes reusable datasets with lineage traces and quality gates.

Data and KPI production

Computes results instead of inventing figures

Bounded analytical tools query, join, clean, rank and aggregate tabular sources. KPIs, validations and chart-ready datasets remain reproducible and linked to their inputs.

Professional deliverables

Creates editable files, not just chat

AC:1 produces PDF and editable Word reports, CSV or Excel workbooks, PNG/SVG/PDF charts and PDF, PowerPoint or self-contained HTML presentations on the AI device.

Mail and calendar connectors

Works with Google Workspace and Microsoft 365

Optional connectors support mailbox searches, human-reviewed email drafts and calendar-event creation. They are disabled by default and only exchange the data needed for the requested action.

Swiss case law · optional add-on

About one million decisions, served locally

The Legal Assistant searches full-text Swiss decisions in French, German and Italian and retrieves the complete source before quoting. The AI device packages OpenCaseLaw's CC0 corpus and MIT-licensed software ↗; runtime search is fully local, with a mirrored update and sovereign rebuild path.

Role-specific assistants for CISOs, DPOs and CIOs extend the same AC:1 foundation with dedicated tools, knowledge and governance policies.

Individual by design

You wouldn't share a work phone. Why share an AI?

The tools that hold your thinking have always been personal. Yet AI, the one tool that reads your documents, drafts and incomplete reasoning, is often pooled across an entire organisation. Neural ICE takes the opposite stance: individual AI, one AI device per professional. A personal work assistant, not a shared corporate chatbot.

Yours

One person, one AI device

Dedicated hardware, models and memory. Your processing is not slowed by another user's workload.

Personal

Shaped by your context

Your private knowledge base, documents and way of working support deep personalisation. A shared service must remain generic; a dedicated AI device can adapt much more closely to your context.

Isolated

Separated by hardware

Two users' data is never processed on the same hardware. Isolation rests on a dedicated AI device, not only on a software policy.

One AI device per professional costs more than a shared account. That premium funds dedicated hardware, stronger isolation and deeper personalisation. Strategic autonomy also depends on a hardware choice.