Same-workstation runtime
Content-processing location: the user’s workstation.
Security architecture
Security starts with deployment choices you can name: the model endpoint, the hardware owner, the approved tools, and the people and devices allowed to connect.
Bridge Mobile access does not determine where inference occurs. It is a separate, authenticated access path to Bridge Desktop.
01 / Deployment boundary
Selected cloud model. Content routed to a cloud model follows that provider’s approved boundary.
Customer-controlled private model. Inference runs on a suitable workstation or server the customer controls.
Alluqi-managed dedicated model. Inference runs off-site on separately contracted dedicated infrastructure; traffic leaves the customer network.
02 / Data paths
Each example identifies the content-processing location. Hosted metadata and the optional encrypted relay remain separate from the model endpoint.
Content-processing location: the user’s workstation.
Content-processing location: the customer-controlled network.
Content-processing location: separately contracted off-site infrastructure.
Content-processing location: the approved cloud provider.
Content-processing location: the endpoint selected for each approved workflow.
03 / Hosted boundary
The hosted service needs enough account and connection information to authorize endpoints. Its design boundary is intentionally narrower than the work flowing between them.
04 / Identity + remote access
The inspected hosted account source supports an emailed sign-in code. Google sign-in is planned and is not currently offered on this site.
A mobile user may sign in to basic account screens before enabling 2FA.
The public remote-access release requires authenticator-app TOTP before pairing a PC or viewing sessions, files, responses, or controls.
Recovery codes provide a one-time fallback. Pairings, devices, and remote authorization must be revocable.
05 / Relay + permissions
Relay boundary. The hosted relay is designed to forward opaque encrypted traffic between approved endpoints without deriving the phone-to-host content keys.
Tool boundary. A model does not automatically gain access to the whole computer, every file, terminal command, browser session, or business system.
Operational boundary. Explicit tools, working directories, user approvals, model choice, local backups, infrastructure access, and incident response remain part of customer responsibilities.
06 / Compliance boundary
Alluqi can be configured around customer-selected infrastructure and security requirements. Compliance depends on the complete deployment, contracts, policies, controls, and operating practices. Alluqi does not claim a certification or authorization unless it is named here with current evidence.