Your server · your circle · your choices
Trust is what lets the real work enter the room.
Nautilo makes the organization server the visible trust boundary. Membership, namespaces, permissions, model routes, connections, and release-current protection determine what stays inside and what crosses by choice.

The current organizational boundary
The server is the trust boundary.
The server belongs to one real organization instead of mixing its long-lived context with a giant unknown SaaS tenant population. Crossings remain explicit choices, not invisible assumptions.
Inside the boundary
- A claimed server with an explicit organization owner
- People, Genies, Rooms, namespaces, and persistent work
- Operator-selected policy, tools, memory, and model routes
Outside the boundary
- Remote model providers selected for a request
- Third-party services reached through approved connections
- Other servers unless a future federation design is implemented
The boundary reduces unknown co-tenants. Authorized members, operators, providers, and connected systems remain part of the threat model.
Membership, namespaces, and permissions
in-progress
The circle is explicit.
Identity and membership determine who is present. Namespaces and permissions bound which context and capabilities are available. The public docs describe the implementation that exists, not an idealized policy system.
In progress: current controls remain subject to release-candidate security review.
Model route choice
in-progress
Private is a spectrum you can see.
Operators can choose among supported model routes, including privacy-oriented providers and major labs. Those routes do not offer identical privacy. Nautilo must expose the choice instead of laundering it into one vague promise.
In progress: provider-specific privacy and retention terms require release-current review.
Release truth
Current boundary. Chosen crossings. Future direction.
Security language advances only when release evidence advances. The page stays useful without pretending unfinished work is complete.
Partial
Organization server boundary
The claimed organization server is the alpha trust boundary. Exact operator and member authority remains documented and reviewable.
- Version
- public-alpha
- Review after
- Owner
- Security and operator owner
- Source
- Security documentation
In progress
Encryption
Scoped cryptographic protection is in progress. Nautilo-wide end-to-end encryption is not yet a shipped public guarantee.
- Version
- public-alpha
- Review after
- Owner
- Security and release owner
- Source
- Security documentation
Planned
Federation
Federation between private servers remains planned future architecture and has no released interoperability path yet.
- Version
- future
- Review after
- Owner
- Architecture and security owner
- Source
- Security documentation
Planned
Models on your hardware
Running open models on hardware you control is a future direction, not a supported public-alpha path.
- Version
- future
- Review after
- Owner
- Model runtime owner
- Source
- Nautilo source
Open is part of the security model
The boundary is visible because the machinery is open.
The source, server, configuration, permissions, provider routes, and public documentation are available for inspection. Exact guarantees remain attached to release evidence and review dates.
Choose your way in.
Pick the door that matches the work in front of you. Both lead into the same system.