Security and access
Review account access, the model endpoint and data handling for your deployment.
Review each access boundary
View 1 of 1: Review each access boundary.
Read the security guidance
Account and device access
Use the intended Control account when approving Link. Keep registration keys, device credentials and session files out of source control, logs shared publicly and screenshots. Review account membership and device records when people or machines leave the organisation.
Network access
The tested local inference endpoint used HTTP. Treat a serving port as a service that needs its own access controls before other machines can reach it. Control sign-in does not automatically protect that port.
Start with loopback access on the same machine. Before enabling remote access, review the listener, authentication and network rules with the person responsible for your deployment. Do not expose the port publicly simply to make an integration connect.
See network requirements for outbound device connectivity.
Data handling
Local inference and hosted management are separate data flows. Review what each application and pipeline sends, stores and logs. The usage-analytics preference concerns product analytics; it is not a switch for every form of telemetry.
Security documentation
For certification evidence, contractual terms, retention requirements or a deployment-specific security review, contact support@locai.co.uk. Obtain the applicable evidence before relying on a certification or compliance claim.