BoltProof
The technical posture behind every Private AI System: a 12-point checklist, zero-trust remote access and ransomware-resistant backup.
A private AI system is only as private as the machine it runs on. Every BoltProof deployment is hardened against the same checklist we'd apply to any small-business server. This page is the technical detail behind that promise.
The AI itself runs on a computer physically located in your office. It is never exposed to the public internet — there is no port forwarding and no public-facing IP address. Staff reach it only over Tailscale, a private encrypted network that authenticates each device individually; a device that isn't explicitly authorized on your Tailscale network simply cannot reach the machine. If you ask us for remote support, we connect the same way, over that same authenticated network, not through a separate remote-access tool or an exposed port added for us — and you can revoke our access at any time from your Tailscale admin console. This is what "private" and "on-site" mean in practice: not that no network connection ever exists, but that every connection is authenticated, encrypted, and under your control.
Full review against our 12-point checklist: 2FA, firewall rules, exposed ports, permissions and patch status — with every gap fixed, not just flagged.
Staff reach the system over Tailscale, never a bare exposed port. No VPN box to manage, no public IP to attack.
3-2-1 backup with snapshot replication, so a ransomware event is a rollback, not a catastrophe.
Access granted only to those who genuinely need it, reviewed on a schedule, not left to accumulate.
Disk space, failed backups, stalled services and unusual logins are flagged before they become incidents.
A written plan for what happens if something goes wrong, agreed before you need it, not improvised during it.
Enforced on every account, no exceptions for convenience.
Removes the single most-targeted username in every attacker's wordlist.
Tailscale or an authenticated reverse proxy only — never a bare exposed port.
Deny by default, allow only what's explicitly needed.
OS and package patches applied on a schedule, not "eventually."
Every open service is attack surface — we close what you don't use.
Three copies, two media types, one copy off-site — always.
Point-in-time rollback so ransomware is an inconvenience, not a catastrophe.
Per-account, generator-made, 16+ characters — the foundation everything else sits on.
Automatic IP blocking after repeated failed logins, with alerting.
Access granted only to those who genuinely need it, reviewed regularly.
Backups disconnected from production so total compromise isn't total loss.
Hardening and the initial security audit are included in every private AI engagement — see Services. If you already have infrastructure and want it audited and hardened on its own, that's a standalone engagement quoted after a free review. Ongoing monitoring, alerting and the monthly restore test are part of on a fixed monthly retainer, no tie-in.
Want your setup reviewed? Message us on WhatsApp Book a Private AI Assessment