Private LLM · Self-hosted AI for companies
Nodus Veritatis is self-hosted, privacy-focused AI for companies: a chat assistant, a searchable document shelf and a model catalogue that all run on your own hardware. A local LLM never touches the network. Everything else waits behind a key only your admins hold.
Joining a team that already runs Nodus? Sign in and ask them for access.
Every model your company uses is registered by an admin. Pick one and watch how far the question actually travels.
Nothing left your network. The weights are on your disk and the answer was generated on your own GPU.
What stays put
Files and context
Upload a contract, a spreadsheet or a survey. When someone asks a question that touches it, the assistant pulls the passages that matter and names the files it read.
Every file carries tags — type, domain, status, the parties involved, a summary — so people can narrow the shelf before they ask, and so nobody retrieves a draft when they needed the signed copy.
Administration
Common questions
A private LLM is a large language model that runs on hardware you control, so prompts, documents and answers stay inside your own network instead of being sent to a vendor. Nodus Veritatis runs local models through Ollama on your own GPU — the request opens no outbound connection at all.
It is private in the only way that can be checked: the traffic. With a local model there is no outbound request to inspect, no retention policy to take on trust and no vendor account holding your history.
The routing table above is the honest version of that claim — it shows, per model, whether the question leaves your network and which host it reaches if it does.
Yes, and that is the usual arrangement. Hosted providers are enabled one model at a time by an admin, under your own API key, stored server-side and write-only.
Only the question and the passages it matched are sent. Your document store, your search index, your chat history and your audit trail never leave your server.
Whatever the model you pick needs — Nodus Veritatis adds no requirement of its own beyond the server running the workspace and its database. Local inference is delegated to Ollama, so its published requirements for a given model are the ones that apply.
If you have no GPU to spare, the same workspace runs entirely on hosted providers under your keys until you do.
Only the person who uploaded it, until they widen it deliberately. Files start private — invisible to colleagues, to admins and to the owner.
Widening attaches a scope: a department, or a position level and every level above it, never below. Each file states where it stands and who put it there.
No. There is no Nodus-operated cloud between your people and their answers, so there is no telemetry setting to go looking for. Chat history, documents, the search index, usage records and the audit trail all sit in your database and on your disk.
Before you take it to the room
Six objections come up, near enough in this order. Each one is answered with the mechanism that settles it — not a reassurance, a mechanism.
Then register a local model and the table above stops at the first row. Ollama reads weights from your own disk and answers on your own GPU; the request opens no outbound connection at all.
Hosted providers are opt-in, one model at a time, by an admin. A model nobody enabled is not in anyone’s picker — there is no setting to remember to switch off later.
So use the contract you have. Provider keys are entered once by an admin, stored server-side write-only, and never shown back in full. The tokens land on your account and your invoice.
What you get on top is a record of who spent it: usage per member, against the limits you set per member, kept in your own database rather than a vendor dashboard someone has to be given access to.
Every file arrives private to whoever uploaded it — invisible to colleagues, to admins, and to the owner. Widening it is a deliberate act with a scope attached.
Choose a department and it reaches that department. Choose a position and it reaches that level and every level above it, never below. Each row on the files page states exactly where it stands and who put it there.
They will not have to. Every answer names the files it drew on, in the thread, at the time it was given. Usage and spend are recorded per member as they happen.
All of it sits in your own database and on your own disk, which is where an auditor would want to find it anyway.
An admin removes them and the seat returns to the pool for the next person. Roles are held per company, so revoking access here does not touch anything they have elsewhere.
A company can require two-factor of everyone; anyone without it is walked through setup before they reach the workspace rather than nagged afterwards.
Internal tools die when they are a worse version of something people already get for free. A public assistant cannot say which clause changed in your supplier contract, because it has never read it. This one has, and it names the file it read — that is the reason someone opens it on a Tuesday instead of the tab they already have open.
And if it does go quiet, you will know in week two rather than month six. Usage is recorded per member, so adoption is a number you already hold: you can see who stopped, ask them why, and give the seat to someone who wants it.
Set it up
Your hardware, your keys. Your team gets an assistant that already knows the company's documents. You get to say exactly how far a question may travel.