ARCHITECTURE & PRIVACY

Your processes.
Your responsibility.
Your data.

Your processes contain more than a task: documents, customer data, internal rules and decisions. Who may see and process that information is a question that belongs in the design of c9n from the start.

The goal is a self-hosted team installation. In fully local operation, your process content is processed and stored within your own environment – including AI when you use your own models.

CONFIDENTIAL PROCESSES

A process reveals more
than a single file.

When people and agents work together, they connect information across several steps. A request becomes an analysis, a draft, feedback and an approval. That combined context can be especially sensitive.

01

Protect people and their data

Enquiries, invoices and personnel matters can contain names, contact details and other personal information. Tasks, comments and work histories can also reveal information about employees and customers.

02

Keep your process knowledge confidential

A workflow shows how you work: which rules apply, who decides and where exceptions arise. Alongside prices, contracts and internal documents, it may contain confidential business knowledge or trade secrets.

03

Share decisions deliberately

Agents need a clear task and the information needed to complete it. A human review can add further details. Each step should therefore receive only the data required for its task.

ARCHITECTURE · LOCAL OPERATION · OPTIONAL CLOUD

What runs locally?
What does the cloud handle?

c9n is designed as a self-hosted team installation on your own computer or server, with shared data and individual user accounts. In fully local operation, process content, documents, agent tasks and results stay in that environment. Local AI uses models on your own computers or network.

Cloud · supporting services

Website and connections

  • GitHub Pages / ReleasesProduct information, the installer and updates.
  • Cloudflare gateway · optionalProvider sign-in, connection status and the credentials required for it.
  • Website contactEnquiries sent by email through Cloudflare and Resend.

These services process their own connection, sign-in or contact data.

Your own environment · computer, server or network

Your local c9n team installation

01

c9n and your team

Processes, tasks, permissions and human approvals.

02

Hermes and GPU management

Run agents; manage model calls, the queue and capacity.

03

Your models / GPUs

AI processes content on your computer or on model servers within your own network.

Shared local storageDocuments, process runs, agent data, results and history stay here in local operation.

The team connects to the same c9n instance. This does not require a separate data copy for each person.

Target design for local operation. Cloud sign-in connects provider accounts; agent and model processing runs within your own environment in the mode shown.

Which data goes to the cloud?

Website visits and downloads generate technical connection data. Optional provider sign-in requires status, identifiers and, where applicable, encrypted credentials stored in the gateway. Using the contact form sends your enquiry through Cloudflare and Resend. These are separate data flows alongside your locally operated processes.

External services are a separate choice

When you configure and use external model APIs, remote GPU servers, Jira Cloud or email integrations, the required content leaves your local environment. A tunnel or cloud proxy may also be involved in transmission. Fully local processing requires your own models and a workflow without these external processing routes.

Development status: This illustrates the planned architecture. The shared package for c9n, Hermes and GPU management and the new process engine are being built. Available connections and supported steps depend on the tested version.

RESPONSIBILITY IN YOUR OWN ENVIRONMENT

Local operation needs
clear rules.

Your own installation gives you control over where processing takes place. Privacy also depends on how you design the process and operate your environment.

Access appropriate to the task
Define which people and agents need which content, who may approve a step and which information is included in a handover.
Storage and retention
Include history, logs, credentials and backups in your decisions. Access protection, retention periods, updates and secure operation of your computers also matter.
Review external services first
Before connecting a service, establish which content is transferred, who processes it and how it is stored or reused. Provider sign-in alone does not answer these questions.
Design privacy into the process
Limit data to what is needed and review purpose, legal basis and data processing agreements where applicable. Local processing supports this work; it does not automatically guarantee GDPR compliance.

This page explains architecture and operating principles. The technical safeguards actually available in a release need to be checked for the specific installation.

Explore processes, agent steps and approvals →