Local-first AI infrastructure

Private by default.
Connected by permission.

We build AI systems for data that should never leave your hands — medical records, financial positions, sensitive learning material. The model runs on your own hardware. When a task genuinely needs frontier capability, it crosses one audited gate, on terms you set.

Perimeter sealed
The Postern gate A sealed local enclave on the left, a wall with a single gate in the middle, and external frontier models on the right. Opening the gate lets a redacted request cross. Your device Local model + your data HEALTH RECORDS POSITIONS Frontier model API
> local inference  active
> egress  blocked
> identifiers on device  0 shared
The problem

Today you choose between capable and confidential

Every serious application of AI to private data runs into the same wall. Neither side of the trade is acceptable to a regulated fund, a clinician, or anyone holding their own medical history.

Cloud frontier models

Genuinely capable, and improving fast. But the data leaves your control, custody is someone else's, retention terms shift under you, and in regulated contexts the compliance burden of proving what happened to a record can exceed the value of the answer.

Local open models

Private, cheap at the margin, and yours. But capped: a quantised model on consumer hardware still loses to frontier reasoning on hard problems, and pure-local products keep losing users at exactly the moment the task gets difficult.

Our approach

A sealed wall with one governed gate

A postern is the small, guarded door in a fortress wall — sealed by default, opened deliberately, watched constantly. That is the architecture, and it is our whole differentiation: we refuse the trade above rather than picking a side of it.

01 / ENCLAVE

Everything local first

Inference and your data stay on your own hardware by default. Nothing about a query or a record leaves your device unless you decide it should.

02 / GATE

One crossing, on your terms

When a task genuinely needs more than local capability, it can reach out — but only through a single, deliberate gate that you control. You decide what may ever cross, or that nothing may.

03 / LEDGER

Every crossing on the record

If something does cross the gate, it's recorded — what happened, and why. Nothing leaves quietly.

What we are building

One architecture, many sensitive domains

The same enclave-and-gate substrate, specialised wherever the privacy stakes are highest and cloud AI is least usable. A few examples:

HEALTH

Personal health assistant

A private assistant over a household's medical history, with per-member isolation and multimodal handling of scans and reports on device. Nothing about a family's health leaves the home unless explicitly released.

FINANCE

Personal finance assistant

Research and portfolio reasoning that keeps positions, holdings and decision records on the user's own machine.

EDUCATION

Private learning assistant

Tutoring and study support over material that is often personal or commercially sensitive.

These are starting points, not the limit — the same architecture applies anywhere sensitive data meets AI.

Company

Who we are

Postern Systems Ltd is a company building local-first AI infrastructure, incorporated in England and Wales.

Legal entity
Postern Systems Ltd, registered in England and Wales. Company number 17389087.
Get in touch

Private AI that doesn't make you choose

If you care about inference at the edge, or about data that should never leave its owner, we would like to hear from you.

hello@posternsystems.com