For work where the name in the database could put someone at risk.
Source protection is not a setting. It is the property that the fewer parties hold your notes, the stronger it is — and every cloud tool adds a party, including the one quietly summarising your text.
What a local-first product actually buys you
It removes a category of risk rather than closing a vulnerability. There is no company to subpoena for your notes, no breach notification you did not initiate, no subpoena disclosure log that records who asked about you.
The honest counterpart: it also does not make you safe. A laptop in a bag is a laptop in a bag. Nothing here defends against a device that is lost, seized or borrowed. What it does is keep your working set to one machine you control, which removes everyone else's involvement from the problem.
The part that usually gives you away
- No cloud AI in the chain. The summarisation runs on your hardware. Your notes are not an input to somebody's model improvement programme, because they are not sent anywhere.
- Research keeps its own discipline. When it fetches a public page it identifies itself honestly, respects robots.txt, rate-limits per host, and checks every redirect hop against private address space. It will not be steered at your network by a malicious link.
- Fetched content cannot instruct the model. Prompt injection is treated as an expected threat: a web page's contents are data, and they get no authority over anything.
- Document reading is local. A PDF or scan is processed on your machine — no upload, no third-party OCR service.
- Provenance on every value. Where a fact came from, and how confident the system is, is recorded. For research that is the point, not an extra.
What it is useful for day to day
Research, with sources attached
Find organisations matching a beat, read their public pages, and extract the facts worth keeping — each with the URL it came from, so a claim is always traceable to the page that supports it.
A pile of documents into a record
Drop in filings, reports, court documents or contracts. They are read locally, classified, and the printed fields are extracted ready to file against the record they belong to.
A story's own bookkeeping
Freelance income, expenses and invoices in a real double-entry ledger. Records that balance to the cent are worth having when an expense claim is contested.
Attribution, in the interface
The claim this page keeps making — that a fact can be traced to the page that supports it — is a property of the record, not of a promise in marketing copy.
Nothing in that second screenshot was retrieved. The model read the record already on the machine and wrote the draft. That is the whole distinction between this and a service that would have had your source documents to send somewhere.
Being clear about the AI
FoundrySuite uses a model to summarise records, extract fields from documents, and draft text. It runs locally, so nothing is transmitted — and it is marked as AI-produced everywhere it appears.
If your work requires that a document be reproduced verbatim, know that a model summary is not that. The extraction is the part that copies fields; the summary is generated text, and it is labelled as such, with a confidence value and the original to check it against.
What it will not help you with
- Operational security against someone with physical access to your machine. Read the security page before assuming otherwise — it says what this does and does not cover.
- Publishing, distribution or secure drop boxes. Those are separate problems with separate, well-established solutions.
- Collaborating with a large distributed team. This is a single-machine product; it is not built for that.