The category that carries most of the argument, because most of the argument is about who is accountable and how you would check.
Governance, written so you can check it.
Governance here means an enforced control and a named owner, not a document. These articles work through where a control actually lives, what happens when it is tested, and what the honest limits are. Each one cites its sources and prints what is not claimed.
What gets filed here.
An article lands in governance when its subject is a control: where it is enforced, who can change it, what it refuses, and what evidence exists that it is doing what the page says. The test for this category is whether a reader could verify the claim in their own environment rather than taking our word for it.
That test rules a lot out. It rules out predictions. It rules out maturity models. It rules out anything whose only support is that a vendor said so, including when the vendor is us.
Three, fully sourced.
Why your models run inside your cloud, not ours.
Whose cloud account the platform runs in decides everything downstream: the compute bill, the encryption keys, the audit records and the exit. With what each major provider publishes about your prompts, a comparison of three hosting models, and ten questions to ask any vendor.
The security owner carries the risk of yes. The operating owner carries the cost of no.
Why an attestation about a vendor's controls cannot resolve a question about your own, and what does: an environment the security owner can inspect.
Data residency is a choice with a price. Here is the price.
Where the law actually constrains you, where it does not, and what a jurisdiction pin costs in capability once you generate the list rather than assert it.
An article can carry more than one category. All three of these turn on an enforced control, so all three are filed under governance; the second is also an operating-model piece and the third is also about residency. The filter on the Pulse index is the fastest way to see the overlap.
Filed elsewhere.
The other categories live on the index, where the filter row narrows the same set of articles without a page reload.
- 01PlatformHow the thing is built: enforcement, isolation, the module runtime, the factory.→
- 02ResidencyWhere data sits, where inference runs, and what a jurisdiction pin costs.→
- 03Operating modelWho decides, who carries the risk, and how an organization actually adopts this.→
- 04Founder notesPositions rather than neutrality, including the ones that cost us work.→
Where the product side lives.
An article argues a position. The governance pages state the current configuration, which is the thing a reviewer needs. They are kept deliberately duller than the articles.
Enforced in cloud policy.
The four denies that apply at every deployment, what each one refuses, and the tests that fail the build if one is weakened.
Posture tiers.
Baseline, Standard and Strict: what each one includes, what it costs, and which one a security review will usually want.
What we do not claim.
The limits, in writing, on one page. Read this before the rest of the section rather than after it.
Your private AI, inside your control ·
The assessment applies the questions in these articles to your own environment, and you keep the deliverable whether or not you proceed.