Most AI tools create compliance risk that offsets every productivity gain. HARBOUR AI eliminates the risk at the architecture level — not through a policy document, but by never moving your data in the first place.
Every time an employee pastes a client document, patient record, or sensitive email into a cloud AI tool, it becomes a data governance event your DPO didn't sign off on.
This is not a privacy policy. This is an architecture. The data never moves because the infrastructure that would move it doesn't exist.
~/.harbour-ai/ on the host machine. Deleting that folder removes every conversation, document, vector index, and user record. There is nothing on any external server to request deletion of.HARBOUR AI's architecture satisfies the specific data handling requirements of every major UK regulated sector — not through a policy statement, but through the absence of data movement.
Download, review, and share. All documents are designed to be used directly in governance reviews, DPO assessments, and IT security approvals.
— REAL QUOTES FROM DPOs AND CISOs COMING SOON —
Are you a DPO, CISO, or IT security lead using HARBOUR AI?
Email LOOSEKEYZ84@PROTON.ME to share your experience.
| DATA GOVERNANCE REQUIREMENT | HARBOUR AI | MICROSOFT COPILOT | CHATGPT / OPENAI |
|---|---|---|---|
| Data stays on your premises | ✓ ALWAYS | ✗ Sent to Azure | ✗ Sent to OpenAI |
| No DPA required | ✓ NONE NEEDED | ✗ DPA mandatory | ✗ DPA mandatory |
| Air-gap / offline operation | ✓ FULL SUPPORT | ✗ Cloud required | ✗ Cloud required |
| Zero telemetry — verifiable | ✓ AUDIT AVAILABLE | ~ Policy only | ~ Policy only |
| You are the sole data controller | ✓ YES | ✗ Microsoft is processor | ✗ OpenAI is processor |
| Tamper-proof audit trail | ✓ SHA-256 CHAIN | ~ Paid add-on | ✗ Not available |
| PII redaction before AI sees data | ✓ 11 UK PII TYPES | ✗ Not available | ✗ Not available |
| Configurable data retention per type | ✓ BUILT IN | ~ Limited | ✗ Provider-controlled |
| GDPR Article 17 — right to erasure | ✓ DELETE FOLDER | ~ Request process | ~ Request process |
| SRA / NHS DSPT / KCSIE compatible | ✓ BY ARCHITECTURE | ~ Requires legal review | ~ Requires legal review |
| Independently penetration tested | ✓ PASSED — June 2026 | ✗ Not applicable | ✗ Not applicable |