We build AI systems for data that should never leave your hands — medical records, financial positions, sensitive learning material. The model runs on your own hardware. When a task genuinely needs frontier capability, it crosses one audited gate, on terms you set.
Every serious application of AI to private data runs into the same wall. Neither side of the trade is acceptable to a regulated fund, a clinician, or anyone holding their own medical history.
Genuinely capable, and improving fast. But the data leaves your control, custody is someone else's, retention terms shift under you, and in regulated contexts the compliance burden of proving what happened to a record can exceed the value of the answer.
Private, cheap at the margin, and yours. But capped: a quantised model on consumer hardware still loses to frontier reasoning on hard problems, and pure-local products keep losing users at exactly the moment the task gets difficult.
A postern is the small, guarded door in a fortress wall — sealed by default, opened deliberately, watched constantly. That is the architecture, and it is our whole differentiation: we refuse the trade above rather than picking a side of it.
Inference and your data stay on your own hardware by default. Nothing about a query or a record leaves your device unless you decide it should.
When a task genuinely needs more than local capability, it can reach out — but only through a single, deliberate gate that you control. You decide what may ever cross, or that nothing may.
If something does cross the gate, it's recorded — what happened, and why. Nothing leaves quietly.
The same enclave-and-gate substrate, specialised wherever the privacy stakes are highest and cloud AI is least usable. A few examples:
A private assistant over a household's medical history, with per-member isolation and multimodal handling of scans and reports on device. Nothing about a family's health leaves the home unless explicitly released.
Research and portfolio reasoning that keeps positions, holdings and decision records on the user's own machine.
Tutoring and study support over material that is often personal or commercially sensitive.
These are starting points, not the limit — the same architecture applies anywhere sensitive data meets AI.
Postern Systems Ltd is a company building local-first AI infrastructure, incorporated in England and Wales.
If you care about inference at the edge, or about data that should never leave its owner, we would like to hear from you.
hello@posternsystems.com