Skip to content
NGARO
How it works Your API FAQ
Join the waitlistJoin the waitlist
How it works Your API FAQ Join the waitlist

Last updated 14 August 2026

Security.

Most security pages ask you to trust a list of adjectives. This one tries to do something more useful: explain the mechanism behind each claim we make, and tell you how to check it yourself. Where the honest answer is "you have to trust us on this one", we say so rather than dressing it up.

Read the privacy policy

On this page

01The short version 02Two tiers, one place your data lives 03What the app does and doesn't send 04The internet toggle 05The one part that isn't local 06What we run, and how to verify it 07The hosted tiers 08The API key 09What we never do 10What we can't protect you from 11Reporting a vulnerability

01The short version

Your documents never reach us. Not encrypted, not briefly, not in a queue somewhere. They are read and indexed on your own computer, they stay there, and so does every conversation you have with your AI. That is true on every tier, including the hosted ones. We have no copy of any of it.

That is a claim about architecture, not about conduct. The difference matters. A company that promises to handle your data carefully is asking you to trust its staff, its contracts, its breach response and its future owners. A company that never receives your data is asking you to trust one thing: that the software does what it says. And unlike the first list, that one is checkable.

Two things do leave, and we would rather you heard them from us than found them yourself. If you host with us, your question and the passages it pulls out of your own documents travel to our compute to be answered, and are not kept. And while you are building an AI, the conversation where you describe what you want runs on a third-party model. Both are set out below.

The rest of this page is how to check the first claim and how to weigh the other two.

02Two tiers, one place your data lives

Everybody installs the same app. The only thing the tier decides is where the model runs: on your own machine, or on rented GPUs we operate. It does not decide where your material lives, because the answer to that is always the same.

Self-hostedHosted
Your documents liveOn your diskOn your disk
The knowledge base livesOn your diskOn your disk
Conversations are storedOn your machineOn your machine
The model runsOn your machineOn our GPU compute
What crosses the wire during a conversationNothingYour question, and the passages it retrieves
What we retain from thatNothingNothing
Needs an internet connectionYes, the app signs inYes
Works if Ngaro shuts downYes, free, permanentlyNo, it would need moving to self-hosted
We could be compelled to hand your documents overNo. We do not have themNo. We do not have them

The last row is the one worth pausing on, because it used to read differently. A legal demand, a compromised server or a future change of ownership cannot produce your documents from us, on either tier, for the simple reason that we are not holding them.

What the hosted tier does change is transit. Answering a question means the question and the relevant excerpts from your documents go out to be processed and come back answered. They are not written down at the other end. If even that transit is outside what you are willing to accept, choose self-hosted: nothing leaves at all, and that is exactly what it is for.

03What the app does and doesn't send

The Ngaro app is signed in. It talks to us, and we would rather give you the list than let a slogan imply it sits there mute. Here is everything that goes out, and everything that does not.

Leaves your machineNever leaves your machine
Who you are: the account you signed in withThe documents you gave your AI
Your subscription state, so the app knows what you are entitled toThe searchable index built out of them
The devices and groups on your account, so you can manage themEvery conversation you have ever had with your AI
Update checks, and crash reports if you leave those onThe names, contents or structure of any file it reads
On the hosted tiers only: your question and the passages it retrieves, sent to be answered and not retainedAnything at all, on the self-hosted tier, during a conversation

Two things are worth spelling out from that table.

  • The index is local, always. Your knowledge base is a searchable index built on your own disk and consulted at the moment you ask a question. It is not synchronised, mirrored or backed up to us, on any tier. We could not restore it for you, which is the same fact from the other side: back it up yourself.
  • Sharing between your own devices does not pass through us. When you host a chat from one machine to another on your account, the two machines talk to each other. We broker who is allowed to connect; we do not carry what they say.

What this is not: a claim that the app works with the network unplugged. It signs in, and an expired or cancelled subscription stops it. We used to promise otherwise and it is no longer true, so it is no longer written here.

04The internet toggle

Your AI has a single switch that decides whether it can search the web. It is off by default. Leave it off and your AI answers only from the documents you gave it; turn it on when you want it to be able to look something up.

The important design decision is where that switch lives. It is not a line in the model's instructions telling it not to go online, and it is not a setting the model can read. It is enforced outside the model, by the application: with the toggle off, no search tool is handed to it in the first place.

That distinction is the whole thing. A rule written into a prompt is a request, and language models can be argued out of requests, by a cleverly worded document, by an instruction hidden in a PDF you fed it, or by accident. A capability that was never granted cannot be argued with, because there is nothing there to persuade.

What turning it on costs you. Search means your question, or a query derived from it, reaches a search provider, so it leaves your machine. That is the trade, it is yours to make, and it is reversible at any time from the settings panel. It has no effect on where your documents live: those stay on your disk either way.

One thing this switch is not, and used to be. It does not put the app itself into an offline mode. The app signs in and stays in touch with us about your account either way; what the toggle governs is the AI's ability to go and look things up. Section 03 is the full list of what that connection carries.

05The one part that isn't local

Here is the caveat we would rather you heard from us.

The onboarding agent that interviews you in plain English, the conversation where you describe what you want your AI to do, runs on a third-party commercial model rather than on yours. It is the one moment in the whole product where an outside AI vendor is involved at all.

So during the build, what leaves your machine is your side of that conversation: the description of the job, the names and structure of what you want it to know, and the settings you choose. What you are describing goes further than nothing, and you should assume the description of your business is readable by somebody other than us.

Your document contents are not part of that. The files you feed it are read, split and indexed by the app on your own machine. Their contents are not uploaded to us and are not sent to the onboarding model. The agent is told what you have, not what is in it.

Once the build is finished, this stops applying entirely. From that moment the third-party model is out of the picture.

06What we run, and how to verify it

The part of this product that actually produces your answers is a part you can check against a public release rather than take on faith.

WhatWhat it doesWhy it matters here
Qwen3The model family that answers your questionsOpen weight and published: anyone can download it, inspect it and run it without us
OllamaRuns that model on your own machine, on the self-hosted tierOpen source, and it is what makes local inference something you can run yourself
A local indexHolds your documents in a searchable form on your diskIt is a set of files in a folder on your computer, not a service you have an account with

If you want to satisfy yourself that the model on your disk is the model we said it was, compare it against the public Qwen3 release. If you want to satisfy yourself that the index is really local, look in the folder.

What we do not publish. The rest of how Ngaro is engineered, the retrieval, the packaging, how hosted inference is orchestrated, is not documented here, and we would rather say that outright than let the sentence above imply more openness than we are offering. It is a small company's only real defence against being copied wholesale.

It is also, deliberately, not what your privacy rests on. Whether we used one library or another changes nothing about where your documents sit. That question is answered in section 02, and it is answered the same way regardless of what is underneath.

Checking the installer you downloaded

When the app ships, every installer we publish will have its SHA-256 checksum listed on this page, next to the download it belongs to. A checksum is a fingerprint of the exact file: if the one you downloaded produces a different fingerprint, it is not the file we built, and you should not run it.

Checking one takes a single command and no software you do not already have. On Windows, certutil -hashfile ngaro-setup.exe SHA256. On macOS, shasum -a 256 Ngaro.dmg. Compare what it prints against what is published here. This is worth doing on any installer from anyone, not only ours.

We are saying this now, before there is anything to download, because a promise made after the fact is worth less. If this page ever offers a download without a checksum beside it, that is a mistake and you should tell us.

Signed, and where you should get it

Ngaro will be distributed through the Microsoft Store on Windows and signed with an Apple Developer ID on macOS. That means your computer can check, before it runs anything, that the app came from us and has not been altered since we built it. On Windows the Store handles that signature; on macOS the app is notarised with Apple, which is what stops Gatekeeper blocking it.

The practical version: get Ngaro from the Microsoft Store, or from a download link on this domain, and nowhere else. An installer that arrives any other way, by email, from a mirror, from a search result that is not us, is one we cannot vouch for, and the checksum above is how you settle the question rather than trusting the source.

07The hosted tiers

Hosting buys you one thing: a bigger model than your computer can run, without buying a computer that can run it. What it does not buy is a copy of your material sitting on our infrastructure, because there isn't one.

Here is the actual sequence when you ask a hosted AI a question. Your app, on your machine, searches your own local index and pulls out the passages that look relevant. It sends those passages and your question to a model running on GPUs we rent. The model composes an answer and returns it. Your app displays it and writes the conversation to your disk. Nothing in that round trip is stored at the far end.

Say the uncomfortable half out loud: excerpts from your documents genuinely do travel over the internet on this tier, every time you ask something. They are processed and discarded rather than filed, but "not retained" is not the same as "never sent", and anyone telling you otherwise is being loose with words. If your threat model does not tolerate transit, the self-hosted tier sends nothing at all.

Everything is encrypted in transit. The GPU compute is rented from a third-party provider, named along with everyone else who touches anything in the privacy policy, and it is given your question and your excerpts for as long as it takes to answer, and nothing else: not your account, not your document library, not your history.

What does not change between tiers: we do not train on your documents, we do not read them for any purpose other than answering your own questions with them, and we do not keep them.

Who can reach the inference layer

The Ngaro team, and nobody else. Hosted inference runs on our provider's vetted tier, in enterprise data centres whose operators hold SOC 2, ISO 27001 and PCI DSS certification, and the provider's own terms prohibit those operators from inspecting what runs on your instance or analysing how you use it. Breaking that rule removes them from the platform. So the honest answer is that the list of people who could look is short, and it is us.

When we would. To debug an incident, and for no other reason. Not to sample quality, not to see what people are building, not to train anything. If that ever needs to change, this paragraph changes first.

What is logged

We do not log your prompts, and we do not log the passages your app sends with them. Not for debugging, not for a short window, not in a form we promise to delete later. There is no prompt log to leak, subpoena or accidentally retain, which is a stronger statement than a retention period would be, and it is the one we can actually make. Our provider keeps its own platform-level operational logs, as any host does, and by default the container storage a job runs in is destroyed with the job.

If something goes wrong

We will notify you within 72 hours of becoming aware of a breach that affects you. Part of that is not our choice: the Privacy Act 2020 already requires us to notify the Privacy Commissioner and the people affected of a notifiable breach as soon as practicable. Putting a number on it is us saying what "as soon as practicable" means to us, so you can hold us to something specific rather than to a phrase. The same commitment, in more detail, is in section 15 of the privacy policy.

If you find the problem before we do, section 11 is how to tell us, and we will not come after you for looking.

08The API key

A finished Ngaro AI can hand out a key against an OpenAI-compatible endpoint, so your other software can talk to it. On the self-hosted tier that endpoint is local, http://localhost:8420/v1, which means automation running on your own network never touches the internet at all. On the hosted tiers the key authorises calls to a model we run, and the answer still comes back through your own machine.

Every key is scoped deliberately narrowly: it reaches one AI and one only, it is rate limited, it can be revoked at any time, and traffic through it trains nothing.

Treat a key like a password. Anything holding it can ask your AI questions, and your AI knows your documents. If one leaks, revoke it, and that is what the revoke button is for, and using it costs you nothing but a reissue.

This is also how a bridge like Make, Zapier or n8n reaches your AI, and it is worth being clear about the consequence: whatever you connect to your key can ask your AI anything it knows, and whatever it does with the answer happens outside Ngaro entirely. We cannot see it and cannot get it back.

09What we never do

  • We do not train any model on your documents, your conversations, or anything else of yours. We do not retrain or fine-tune models at all.
  • We do not read your documents for any purpose other than answering your own questions with them.
  • We do not sell, rent or trade your information.
  • We do not use your content to improve our product, benchmark it, or demonstrate it.

The first of these is not really a promise at all. It is a description of a situation. Your index never leaves your disk, on any tier, so there is nothing for us to train on even if we wanted to.

10What we can't protect you from

A security page that only lists strengths is marketing. These are the real limits.

  • Your own machine. If your computer is compromised, stolen unencrypted, or shared with someone who shouldn't read your documents, a local AI is no safer than the files it was built from. Local means the risk moves to you, not that it disappears. Full-disk encryption and a password are doing more work here than we are.
  • What you choose to share. If you hand the address and key to your whole team, everyone holding it can ask your AI anything it knows. The same goes for the devices and groups on your account: adding a device is granting it access to the conversations you share with it.
  • The AI being wrong. Grounding an answer in your documents makes it much more likely to be right. It does not make it certain. It can misread a table, miss a document that was relevant, or state something confidently that the source does not support. Check anything that matters.
  • Instructions hidden in your own documents. If you feed it a file containing text written to manipulate a language model, that text is now part of what it reads. Leaving the search toggle off narrows what such an instruction could accomplish, since an AI with no search tool has no obvious way to send anything outward, but it is a real category of risk and we would rather name it than pretend it away. It matters most if you have connected your AI to other software through the API.
  • Anything you paste somewhere else. Ngaro protects the documents you give Ngaro. It cannot help with the ones that go into a browser tab.

11Reporting a vulnerability

If you find a security issue, please tell us before you tell anyone else, and we will work with you rather than against you. We will not pursue legal action against anyone acting in good faith to find and report a problem.

Security reports go to ngaro.help@gmail.com with "security" in the subject line. We aim to acknowledge every report within three business days. That is a promise to reply, not a promise to have fixed it by then: triage takes as long as it takes, and we would rather tell you where it is up to than go quiet on you.

There is no bug bounty. We are a small company and cannot fund one, and saying so plainly seems better than letting you find out after the work. What we can offer is the part that actually matters: we will not come after you for looking.

These same details are published at /.well-known/security.txt in the RFC 9116 format, which is where security tooling looks first.

Ngaro is based in Tāmaki Makaurau, Auckland, Aotearoa New Zealand.

NGARO
NGARO

Ngaro: to be hidden, unseen. A private AI you build yourself and keep on your own machine. Made in Aotearoa New Zealand.

Join the waitlist

Product

How it works Your API FAQ

Company

Join the waitlist About Blog

Legal

Privacy policy Terms of service Security

© 2026 Ngaro. All rights reserved.

PrivacyTermsngaro.help@gmail.com