DT

Written and reviewed by DeviceterraDeviceterra editorial team · Updated September 9, 2026

KEY TAKEAWAY

Running AI locally removes one cloud risk. It does not automatically protect every file, app, user, or connection.

TRY IT YOURSELF

Complete a basic safety check

Running a model locally removes one cloud risk, but it does not protect an unlocked laptop, public model port, unsafe plugin, or badly stored backup.

  1. 1

    Draw the data path

    Write every place a prompt or file goes, including the chat app, model, search index, logs, plugins, and backups.

  2. 2

    Disconnect unneeded online tools

    Turn off web search, cloud sync, analytics, or plugins that are not required for the private task.

  3. 3

    Check the local service

    Keep Ollama on its normal local address. Do not forward port 11434 from your router to the internet.

  4. 4

    Protect the computer

    Use a login password, disk encryption, screen lock, and current security updates.

  5. 5

    Test with fake private data

    Use made-up customer records. Check logs, exports, backups, and user permissions before adding real records.

How to know it worked
  • No model service is open directly to the public internet.
  • Users see only the documents they are allowed to see.
  • You know where prompts, logs, and backups are stored.
UNDERSTAND THE DETAILS

Use the explanations below when you want to know why each step matters.

01

Keep sensitive information out of the prompt itself

If the model does not need a customer’s identity, remove it before sending the prompt. Replace names with stable labels such as Customer A and remove phone numbers, addresses and account identifiers. Keep the mapping outside the AI application.

Redaction is not perfect: a rare job title, event or combination of details may still identify someone. Review the remaining text. For tasks that require exact records, restrict access and processing to the approved system instead of pretending the data is anonymous.

02

Test the complete boundary with invented records

Create a fake record with a distinctive marker. Run the normal task, then check chat history, application logs, exports, document indexes and backups for that marker. Decide who can read each copy and how it will be removed.

Test a second user who should not have access. The search layer must enforce permissions before it passes text to the model. Asking the model to hide unauthorized information is not an access-control mechanism.

What a pass means

A pass applies to the settings and workflow tested. Adding a cloud model, search plugin, remote backup or new user role requires another check.

03

Draw the full data path

List every place that receives a prompt or document. This may include the chat app, AI model, document search, speech tool, web search, plugins, logs, and backups.

Mark which parts stay on your computer and which parts contact the internet. Turn off cloud features you do not need.

04

Keep the model service private

Ollama normally accepts requests only from the same computer. Its local service does not ask for a password.

Do not open that service directly to the internet. For a team, place it behind a protected app or private network with user accounts and access rules.

Important warning

Changing a network address does not create security by itself.

05

Protect documents

  • Encrypt computers and backups.
  • Check permission before searching a document.
  • Keep document groups separate by role.
  • Do not store secrets users should never find.
  • Show sources beside important answers.
  • Decide when files, indexes, and chats are deleted.
06

Treat files and tools as untrusted

A document can contain hidden instructions that try to control the AI. This is called prompt injection.

Keep document text separate from trusted rules. Give connected tools only the access they need. Require a person to approve important actions.

07

Minimum safety checklist

  • Download models and apps from trusted sources.
  • Keep the model port off the public internet.
  • Give each user only the access they need.
  • Set rules for logs and backups.
  • Test for data leaks and harmful document instructions.
  • Keep a shutdown and recovery plan.
RESEARCH SOURCES

Official facts and real user evidence

Official documentation supports product and model facts. Community discussions show real setups, failures, and questions. A community result is supporting evidence, not a promise that another computer will perform the same way.

MAKE IT PRACTICAL

Find a model your computer can run.

MamiLens checks your hardware and shows a careful starting point.

Run the free compatibility check →

This guide is educational. Model software, licenses, and hardware support can change. Check official sources before an important deployment.