LionBox

Security overview

Security architectureand data handling.

LionBox performs inference on the appliance inside the customer network. This page documents the default boundaries, controlled exceptions, administrative responsibilities and controls that are still being finalized.

Default security posture

Inference locationOn appliance
Outbound appliance accessOff
Internet searchOff by default
Update initiationAdministrator

01

System boundary and request path

Normal AI use requires an authorized browser, the office network and LionBox. External inference is not part of this path.

Normal inference path

Local Browser

Authorized user

Private LAN

Ethernet or Wi-Fi

LionBox

Local GPU inference

The internet gateway can be disconnected while this path remains available.

Boundary statement

Processing
Selected AI models run on the appliance GPU.
Address
Authorized users access the workspace at lionbox.local.
External API
No external inference API is required for normal operation.
Internet
Local chat and indexed knowledge remain available offline.
PathDataTransportDefault
Browser → LionBoxPrompts, attachments and responsesPrivate office LANActive
LionBox → external AI APINo inference trafficNot requiredDisabled
Admin phone → LionBoxAuthorized software and model bundles onlyPaired transfer pathAdmin initiated
LionBox → internet searchScreened request, only when enabledControlled exceptionOff

02

Control matrix

Implemented architectural decisions are separated from launch controls that remain under definition.

Network

Normal inference remains on the office network. The appliance does not require a public inference endpoint.

Defined

Identity

The owner pairs the appliance, creates users and assigns access to approved knowledge spaces.

Defined

Workspace isolation

User requests remain separated. Administrators manage access without reading private conversations.

Defined

Updates

The administrator downloads authorized bundles to the phone and transfers them to the paired appliance.

Defined

Storage

The intended launch design supports encryption using a dedicated USB key. Removing it prevents encrypted storage from being read.

Launch design

Audit logs

Event coverage, retention and administrator visibility are not yet finalized.

In definition

Backups

Backup destination, encryption and recovery workflow are not yet finalized.

In definition

03

Data handling and diagnostics

User content and appliance health data are separate categories. Diagnostic information does not include the content of AI work.

Remains within the customer environment

User and company content

  • Prompts and user questions
  • Generated answers
  • Uploaded document content
  • Private workspace conversations

Available for requested troubleshooting

Appliance health data

  • Appliance temperature and load
  • Installed software version
  • Performance measurements
  • Standard functional test results

Internet search

Disabled by default. An administrator can enable it; a search request is screened before leaving the local workflow.

Software and models

Downloaded by the administrator's phone and transferred to the paired appliance. LionBox does not fetch them directly.

Pairing channel

Used during administrator setup and for controlled transfer operations initiated from the mobile app.

04

Administrative and user boundaries

Administrative access is separated from the content of individual workspaces.

Administrator can

  • Assign the appliance to an owner account
  • Create and disable user accounts
  • Set knowledge-space permissions
  • Initiate updates and optional search

Administrator cannot

  • Read a user's private requests
  • Read private workspace conversations
  • Receive prompt content through diagnostics
  • Bypass the configured workspace boundary

Organization remains responsible for

  • Office network security
  • Administrator credentials
  • Physical access to LionBox
  • Policies for optional external features

05

Offline verification procedure

A customer can verify that normal inference does not depend on an internet connection.

Expected result

The local workspace loads, the installed model responds and approved indexed knowledge remains available. Internet search is unavailable.

  1. 01Complete setup and install the selected model.
  2. 02Keep the office LAN active, but disconnect its internet gateway.
  3. 03Open lionbox.local from an authorized computer on the same network.
  4. 04Send a test prompt and query an indexed document.

Open controls

Audit logging and backup behavior are still being defined.

Event coverage, retention periods, backup destination, encryption and recovery procedures will be documented before purchase and shipping. They are not presented as completed controls.

Need this architecture reviewed against your environment?

Send us your network topology, deployment requirements or security questions.

Contact the technical team