Privacy tiers
Asking an AI assistant about a client file raises a question that ordinary software does not: where does the text of my question go? kOS answers it with two tiers you can choose between, and a separate control for what leaves your machine inside an attachment.
Cloud Secure — the default
Section titled “Cloud Secure — the default”Cloud Secure is how kOS behaves unless you change it. Your data is stored in the European Union, encrypted, and never used for training without your explicit consent:
- Data stored in the European Union
- Encrypted in transit and at rest
- A data processing agreement per GDPR Article 28, and a sub-processor list
- Not used for AI model training without your explicit consent For Lex, KlusAI additionally presents this tier as compliant with Romanian professional-secrecy obligations (Law 51/1995) and the Deontological Code.
AI processing under Cloud Secure runs through KlusAI’s model providers. That is the trade: the strongest models, EU-resident storage, contractual protection — but your question does reach a third-party AI provider.
Super Private — KlusAI Outpost
Section titled “Super Private — KlusAI Outpost”Super Private closes that last gap. AI processing moves to a KlusAI Outpost — a node on your own premises — so your questions never reach a third-party AI provider at all:
- Everything in Cloud Secure, plus:
- AI inference runs on your own hardware
- Questions never reach third-party AI providers
- No dependency on external AI services
Because inference happens on hardware you already own, there is no per-question inference cost.
Switching it on
Section titled “Switching it on”Super Private is a per-conversation switch, not an account-wide mode. You turn it on for the conversation you are in, and it stays on for that conversation.
- Open a conversation with the assistant.
- In the composer’s icon row, click the lock. Hovering it first shows a panel titled Super Private Mode explaining the current state.
- The lock turns green with a dot, the panel reads Active — on-device AI, and a small Private badge appears next to the conversation title. When it is off, the panel reads Off — using cloud AI.
Click the lock again to switch that conversation back to cloud AI.
While Super Private is active you can tell at a glance: the Private badge in the header, a green ring around the assistant’s avatar on every reply, and — if you hover the token count under the composer — a Private session panel reporting that answers are routed to your Outpost, with a cost of zero.
The assistant’s own description of the mode is that your conversations are processed entirely on your local hardware and nothing leaves your network.
When a local model can’t do the job
Section titled “When a local model can’t do the job”Not every model that can run on local hardware can use the assistant’s tools. If the model configured for your Outpost cannot do what a request needs, the assistant says so instead of quietly answering worse, and gives you two choices: send this one request to the cloud, or continue with local AI anyway.
Sending to the cloud applies to that single request only. It does not turn Super Private off for the conversation.
The separate control: PII protection for attachments
Section titled “The separate control: PII protection for attachments”Alongside the lock sits a shield: PII protection. This is a different question from which AI processes your request — it governs what text is sent when you attach a file.
- On — personal data is removed from attachments before sending. In the product’s own words: it removes names, addresses and other personal identifiers from attached files (PDF, DOCX and similar) before they reach the AI.
- Off — original attachment text may be sent to the AI.
Knowledge-base documents are not affected by this toggle; it applies to files you attach to a conversation.
Some deployments require attachment screening. Where that is the case the shield is fixed on and cannot be clicked — a policy your administrator has set, not a fault.
Which tier do I have?
Section titled “Which tier do I have?”The lock in the composer tells you. If your organization has no Outpost, the lock will report an error rather than switching, and you are on Cloud Secure.
If you are evaluating which tier you need, the short version: Cloud Secure is appropriate wherever an EU-resident processor under a GDPR Article 28 agreement is acceptable. Super Private is for firms whose obligations or risk appetite require that client material never reach an external AI provider at all.
For the full list of what KlusAI commits to under either tier, see Security and compliance.