The outcome
Compare and use models without exposing credentials, confusing provider privacy boundaries, or losing the local workspace.
Step by step
A workflow you can repeat.
- 01
Install a verified official release, enable operating-system encryption and account lock, update the system, and create an encrypted backup before importing any existing workspace.
- 02
Choose approved providers, review their retention and training terms, create dedicated low-privilege keys, retain official endpoints, and allowlist only evaluated chat and embedding models.
- 03
Build one assistant with narrow instructions, disable unneeded search and tools, and run a frozen non-sensitive benchmark for quality, routing, context, errors, latency, and cost.
- 04
Classify conversations and files before use, confirm exactly which provider receives each request, and avoid shared-device profiles, screenshots, logs, clipboard leaks, and unapproved cloud backups.
- 05
Configure an encrypted WebDAV or S3-compatible backup if needed, test restore on a separate profile, rotate keys, review telemetry settings, and repeat backup before every upgrade.
Working standard
What good use looks like.
- Use dedicated provider keys.
- Know every request's remote destination.
- Test encrypted backup and restore.
Official references