Security & diligence · the on-site system
Your data. Your control.
Built-in controls protect information and keep approvals with your team.
Data boundary
Nothing sensitive leaves the building.
One door out, and everything through it is recorded.
The record of what leaves →Action boundary
Nothing happens outside the firm without a person.
The machine stops, and the AI cannot talk its way past it.
The run record →How the on-site system is protected.
If a claim cannot be checked on your own machine, we do not make it here.
Approved software only
A security chip checks the software at every start.
Keys protected by hardware
The keys that unlock your data never leave its security chip.
Your data. Your keys.
A backup drive stays in your office, and if you leave, we delete everything in front of you.
Updates you approve
Each update's seal is checked before anything runs.
Every outbound request recorded
Anything on your never-send list is refused, even if the code-word step fails.
No way in
We get only a simple health signal — never your files.
View an example outbound record
EGRESS PROXY · LIVE LOG
today · 5 payloads · 1 refused (canary) · 0 entities out
- 03:41:22 #4,811 1,204 B pass forwarded
- 08:02:10 #4,819 968 B pass forwarded
- 09:14:55 #4,822 1,411 B pass forwarded
- 09:51:03 #4,826 742 B pass forwarded
- canary test — 2,140 B HIT refused, logged
— inbound: 4 signed update manifests, verified
PAYLOAD 03:41:22 · IN FULL
{ "task": "compare_candidates",
"role": "[ROLE_2]",
"client": "[CLIENT_A]",
"budget": "[AMOUNT_7]",
"ask": "which profile fits, and why" } no names · no figures · no filenames the key to the code words stays on the machine
Evidence and limits
What we test. What we don’t promise.
Certain by design for fixed patterns; layered beyond; a physical stop behind both. Zero leaks in all testing to date — every exit logged, open to you.
No system is unhackable. We show the tests, the results and their limits.
DILIGENCE PACK — WHAT YOUR IT TEAM RECEIVES
- Network diagram, with the machine's one route out marked
- Signed export of the record of what left, for any date range
- Start-up integrity record from the machine's own security chip (TPM)
- How the tests were run, the full list of protected details, and the canary results
- Where the machine stops for a person, workflow by workflow
- Backup, key-holding and replacement-unit procedures
- Deletion procedure, with proof that what the machine learned has been removed
The difference
From recording work to doing it.
midas works across your existing tools, with your team in control.
A stack of per-seat subscriptions
- Software your people type the work into
- Priced per seat, per add-on, per year
- Data held by each vendor, on their terms
- Several vendors, shared accountability
- Your people still do the work; the system remembers it
midas — a machine you own that does the work
- The machine works those systems for your people
- Ready-made workflows for your trade, with every change tracked
- Limits built into the hardware, and a record of what leaves, open to inspection
- What it learns from your team stays with you, and can be deleted
- One machine, one managed service, one accountable party
The software you were about to buy is a place to record the work. This does the work.
It is also a fraction of the price. That is the second argument, not the first.
Send your IT lead. They can read the record themselves.
We'll hand over the diligence pack in the session, not three weeks later.