BoltProof

Security & hardening

The technical posture behind every Private AI System: a 12-point checklist, zero-trust remote access and ransomware-resistant backup.

A private AI system is only as private as the machine it runs on. Every BoltProof deployment is hardened against the same checklist we'd apply to any small-business server. This page is the technical detail behind that promise.

The security model in plain terms

The AI itself runs on a computer physically located in your office. It is never exposed to the public internet — there is no port forwarding and no public-facing IP address. Staff reach it only over Tailscale, a private encrypted network that authenticates each device individually; a device that isn't explicitly authorized on your Tailscale network simply cannot reach the machine. If you ask us for remote support, we connect the same way, over that same authenticated network, not through a separate remote-access tool or an exposed port added for us — and you can revoke our access at any time from your Tailscale admin console. This is what "private" and "on-site" mean in practice: not that no network connection ever exists, but that every connection is authenticated, encrypted, and under your control.

What's included in every deployment

Security audit & hardening

Full review against our 12-point checklist: 2FA, firewall rules, exposed ports, permissions and patch status — with every gap fixed, not just flagged.

Zero-trust remote access

Staff reach the system over Tailscale, never a bare exposed port. No VPN box to manage, no public IP to attack.

Ransomware-resistant backup

3-2-1 backup with snapshot replication, so a ransomware event is a rollback, not a catastrophe.

Access control review

Access granted only to those who genuinely need it, reviewed on a schedule, not left to accumulate.

Monitoring & alerting

Disk space, failed backups, stalled services and unusual logins are flagged before they become incidents.

Incident response planning

A written plan for what happens if something goes wrong, agreed before you need it, not improvised during it.

The 12 points we apply to every deployment

1. Two-factor authentication

Enforced on every account, no exceptions for convenience.

2. Default admin disabled

Removes the single most-targeted username in every attacker's wordlist.

3. No direct internet exposure

Tailscale or an authenticated reverse proxy only — never a bare exposed port.

4. Configured firewall

Deny by default, allow only what's explicitly needed.

5. Automatic updates

OS and package patches applied on a schedule, not "eventually."

6. Unused services disabled

Every open service is attack surface — we close what you don't use.

7. 3-2-1 backup strategy

Three copies, two media types, one copy off-site — always.

8. Snapshot replication

Point-in-time rollback so ransomware is an inconvenience, not a catastrophe.

9. Strong, unique passwords

Per-account, generator-made, 16+ characters — the foundation everything else sits on.

10. Auto-block & login limits

Automatic IP blocking after repeated failed logins, with alerting.

11. Least-privilege permissions

Access granted only to those who genuinely need it, reviewed regularly.

12. Air-gapped backups

Backups disconnected from production so total compromise isn't total loss.

From audit to hardened

  1. Audit. Review against the 12-point checklist, documented gap by gap. Included with every new Private AI System.
  2. Fixed quote. For an audit of existing infrastructure not bought from us, a fixed price to close every gap, sent within 24 hours.
  3. Harden. We implement every fix — 2FA, firewall, remote access, backups — end to end.
  4. Verify & handover. We test the hardened state and hand over full documentation.

Pricing

Hardening and the initial security audit are included in every private AI engagement — see Services. If you already have infrastructure and want it audited and hardened on its own, that's a standalone engagement quoted after a free review. Ongoing monitoring, alerting and the monthly restore test are part of on a fixed monthly retainer, no tie-in.

Questions we get asked

Is this only for BoltProof hardware?
The 12-point checklist and audit apply to any small-business server or NAS, including infrastructure you already own. The Private AI System price above only covers hardware we supply.
What if we already have an IT provider?
We work alongside them and hand over full documentation of everything we change.
Does hardening slow anything down?
No noticeable difference for normal use. The checklist changes configuration, not the hardware doing the work.

Want your setup reviewed? Message us on WhatsApp Book a Private AI Assessment