Nothing leaves your network
Indexing, embeddings, search, and the AI that writes answers all run on the appliance we ship you. No client document is sent to a third-party cloud or public AI service — the claim cloud tools cannot make.
Security & privacy
FileFerret was built for material that cannot be handed to a public cloud. Everything runs inside your walls, every access is recorded, and no client file is ever sent to an outside service.
Indexing, embeddings, search, and the AI that writes answers all run on the appliance we ship you. No client document is sent to a third-party cloud or public AI service — the claim cloud tools cannot make.
We ship you a private, preconfigured FileFerret appliance, install it, and support it for years — running in a location you choose. No multi-tenant platform, no outside vendor staff with standing access, no surprise terms-of-service change touching privileged material.
Per-client collections and per-user access control keep ethical walls in place. Staff only reach the matters they are cleared for, and every access is recorded.
A complete activity log captures every login, search, and file open — so you can answer, with evidence, exactly who touched what and when.
AI you can answer for: every generated answer cites its sources, a full audit log records every action, and your files are never used to train an outside model. The professional stays in control — the AI shows its work.
Air-gapped by design
Your files, the FileFerret appliance, and your staff live on one side — inside your network. The public internet and cloud AI live on the other. No client file ever crosses that line, in any posture. Keeping your client data in is the architecture itself, not a setting you have to trust someone to honor — and what can cross is narrow and on your terms: signed updates in, scrubbed diagnostics out, never a client document.
Support, without a standing way in
Defense buyers get the absolute air-gap guarantee; professional-services firms get a convenient-but-controlled remote option. Same product, a configurable posture — and remote support is opt-in, off by default, and never required to get help. Either way, no client file ever crosses — the postures differ only in whether a controlled, non-client-data channel exists for updates and support.
Convenient, but controlled. When you need help, the appliance can make a customer-keyed, egress-only connection for remote support — opened only when you choose, audited end to end, and far better than a truck roll for every ticket.
The absolute guarantee. No connection path exists at all. Remote support is off the table by policy, so support runs by phone, screen-share on your terms, hand-carried scrubbed diagnostics, and on-site visits.
The load-bearing decision
When you do open the glass, support reaches a constrained plane, not your filesystem. That is the feature, not a limitation we hide: the privilege boundary is never crossed.
Support gets a purpose-built console — restart services, re-run indexing, read scrubbed logs and metrics, check GPU / disk / auth health, rotate keys — that structurally cannot open or export a client document, read index content, or see query text. Most real tickets are solvable entirely from it.
For anything beyond the console, the default is screen-share with your admin’s hands on the keyboard: we guide, your firm acts, your firm sees everything in real time. A standing “session active” indicator and an instant kill switch. No independent vendor access.
Full session recording — commands, actions, duration, who authorized — written to the tamper-evident log. You hold a complete, reviewable receipt of every support action we ever take. Every time we touch your box, you hold the record.
No standing support account. Access is a short-lived credential that requires both your authorization and our support identity to open — neither side alone can break the glass — scoped to least privilege and auto-expiring.
Remote support is opt-in and off by default — and never a condition of being supported. Choose a fully no-remote path (phone, customer-driven screen-share, hand-carried scrubbed diagnostics, on-site) and lose nothing.
For law firms, a vendor with any path to privileged material can raise confidentiality and vendor-supervision questions under the rules of professional conduct. A support plane that cannot read client content is exactly the kind of reasonable safeguard those rules look for. This is not legal advice and the rules vary by jurisdiction — your counsel’s call — but the constrained plane answers the question before it is asked.
Questions firms ask
No. FileFerret runs on a private appliance we ship to your office. Indexing, search, and the AI that writes answers all run on that appliance, inside your own network. No client file is sent to an outside cloud or public AI service.
No. We ship you a private, preconfigured FileFerret appliance — hardware and software together — install it, and support it for years to come. It stays in your office, under your control; nothing ever runs in our cloud.
Documents (including scanned, image-only PDFs via OCR), images, audio, and video. Recordings are transcribed and images are described, so spoken words and on-page text are all searchable.
Each client’s material lives in its own collection, and administrators control exactly which staff can search which collection. Every access is written to an audit log.
On the private appliance we ship you — on-premises or in a private environment you control. We size it, install it, and support it for years.
Tell us about your firm and the records you hold. We’ll scope your needs, ship and install your FileFerret appliance, train your team, and support you for years to come. Reach us through the contact page to get started.
We’ll scope your firm’s needs, ship and install a private FileFerret appliance, train your team, and support you for years to come. No client data leaves your office — ever.