The outcome

Compare and use models without exposing credentials, confusing provider privacy boundaries, or losing the local workspace.

Step by step

A workflow you can repeat.

  1. 01

    Install a verified official release, enable operating-system encryption and account lock, update the system, and create an encrypted backup before importing any existing workspace.

  2. 02

    Choose approved providers, review their retention and training terms, create dedicated low-privilege keys, retain official endpoints, and allowlist only evaluated chat and embedding models.

  3. 03

    Build one assistant with narrow instructions, disable unneeded search and tools, and run a frozen non-sensitive benchmark for quality, routing, context, errors, latency, and cost.

  4. 04

    Classify conversations and files before use, confirm exactly which provider receives each request, and avoid shared-device profiles, screenshots, logs, clipboard leaks, and unapproved cloud backups.

  5. 05

    Configure an encrypted WebDAV or S3-compatible backup if needed, test restore on a separate profile, rotate keys, review telemetry settings, and repeat backup before every upgrade.

Working standard

What good use looks like.

  • Use dedicated provider keys.
  • Know every request's remote destination.
  • Test encrypted backup and restore.

Official references

Check the current product documentation.