Where Your Data Actually Lives
De-Cloud AI runs in two places. The AI model runs on hardware you own, and a small set of well-established cloud services host the web application around it. Here is every vendor in the system, and exactly what each one holds.
Where each kind of data lives
| Data | Where it lives |
|---|---|
| Every prompt your staff send | Your AI server. Never transmitted off it. |
| Every answer the AI generates | Your AI server. Never transmitted off it. |
| The AI model itself | Your AI server, run by Ollama. |
| Document conversion and the search index | Your AI server. |
| Uploaded files, at rest | Cloudflare R2, encrypted. |
| Accounts and chat history | Neon Postgres, isolated per organization. |
| Password resets and invitations | Resend. |
Your AI server (Ollama)
Source: ollama.com | Owner: your organization
- Runs open-source models locally through Ollama. No model provider account, API key, or outbound request is involved in producing an answer
- Prompts, answers, document conversion, and the search index are all produced on this machine
- Sits in a lockable space on your own network, on hardware your organization owns outright
- Patched, updated, and health-monitored remotely by NextWrite, with no access to your prompts, your answers, or your documents
This is what makes De-Cloud AI different from every other option. Because the model runs here, no outside AI company receives your prompts, your documents, or anything generated from them.
Vercel
Source: vercel.com/security | Owner: Vercel, Inc.
- SOC 2 Type II, GDPR, CCPA compliance
- Encryption in transit and at rest
- Identity & access management, secure global infrastructure
- Continuous scanning, third-party audits, incident response
We inherit Vercel's secure hosting and CI/CD infrastructure, ensuring NextWrite deployments are monitored and protected against threats.
Neon
Source: neon.com/security | Owner: Neon.tech
- SOC 2 Type II compliance
- Encryption at rest and in transit, role-based access
- Network isolation, monitoring, automated failover
We inherit Neon's secure managed Postgres environment for NextWrite's data storage and orchestration.
Cloudflare R2
Source: cloudflare.com/trust-hub | Owner: Cloudflare, Inc.
- SOC 2 Type II, ISO 27001, GDPR compliance
- Encryption in transit and at rest
- Scoped, short-lived access credentials rather than shared keys
- DDoS protection and continuous monitoring
Uploaded files are stored here. Conversion and indexing happen on your own AI server, so Cloudflare holds the stored file and never the searchable content derived from it.
Resend
Source: resend.com/docs/security | Owner: Resend, Inc.
- SOC 2 Type II, GDPR compliance
- TLS 1.3+ encryption, 30-day global backups
- Annual pen testing, vulnerability scans, endpoint protection
- MFA for all staff, least-privilege access model
We inherit Resend's secure email delivery pipeline, ensuring messages generated by NextWrite are delivered with enterprise-grade protection.
NextWrite's Layer of Security
- Role-based access control (RBAC): only authorized users can access sensitive data.
- Audit logging: all AI interactions and outputs are traceable and reviewable.
- Human-in-the-loop checkpoints: staff make final decisions, reducing AI misuse risks.
- On-premises by default: the AI model runs on hardware you own, so the most sensitive processing never leaves your building.