You approve the material
An administrator adds a document and types a confirmation sentence to record that it is approved company knowledge. Nothing is indexed without that step.
For teams whose documents cannot leave the building
Legal, clinical, financial, defence: the work where pasting a contract into a chatbot is not an option. OwnMind runs on hardware you control, answers only from material your team has approved, and shows the passage behind every claim — or tells you plainly when there isn't one.
Ready now? Request a private pilotRead the security model
Remote access uses disclosed network and identity providers. OwnMind is not zero-knowledge and is not end-to-end encrypted from the browser to the host.
The artifact
Confidence is not the product. Checkability is. Every answer arrives with the excerpt it was built from, so the person who has to sign off on it can verify the claim in about ten seconds against a document your team already approved — without taking anyone's word for it.
Can a fixed-term contractor claim the overtime rate for weekend on-call?
Not at the overtime rate. Fixed-term contractors are eligible for on-call compensation1.1, but the multiplier applies to permanent staff only2.1. Weekend on-call is paid at the standard hourly rate, and anything past the rostered window needs written approval from the engagement owner in advance2.2.
Fixed-term contractors are eligible for on-call compensation from their first rostered shift.
The 1.5× overtime multiplier applies to permanent employees only.
Hours worked beyond the rostered on-call window require written approval from the engagement owner in advance.
What is the parental leave allowance?
I couldn't find enough evidence for that answer in the approved company documents.
How it runs
An administrator adds a document and types a confirmation sentence to record that it is approved company knowledge. Nothing is indexed without that step.
Approved uploads are sent to your deployment for parsing and indexing in your own Postgres. They are never sent to a third-party model provider.
A question is matched against approved material by meaning and by wording at once, so the right section is found whether the reader used your vocabulary or their own.
Generation happens on your hardware. The answer streams back with a numbered citation for each passage it used, and says so plainly when the approved sources do not cover the question.
Deployment
OwnMind is installed into infrastructure your organization already controls. There is no OwnMind-operated inference tier, and no request to a third-party model API.
Remote access uses disclosed network and identity providers. This is not zero-knowledge and not end-to-end encrypted.
What listens, and where
Generation, embeddings, and the database bind to the loopback interface. The application is the only thing reachable from outside, and only through your identity gateway.
Governance
Answers are drawn from the collection your administrators approved. Retrieved text is treated as untrusted reference material, never as instructions.
Each supporting passage arrives as a numbered citation carrying the document name, its locator, and the exact excerpt used.
When the approved material does not support an answer, the assistant says it was not found rather than filling the gap.
Access is gated by your identity provider, and the API independently validates the signature, issuer, audience, and expiry of every request against an explicit allowlist.
Adding, listing, and deleting company knowledge is written to the host's audit log under a stable pseudonymous actor identifier.
Conversations are temporary. Prompts and answers are not written to disk, and prompts, responses, and source excerpts are never logged.
Comparison
How to start
Every engagement starts with a short pilot on OwnMind's evaluation host, using material that is safe to share. If the pilot earns its place, we scope a deployment around your documents, your identity provider, and your hardware, and build it for you.
Stage 1 · Seven days
Your team tries OwnMind on our evaluation host, with sample material.
Reached through disclosed network and identity providers. Not for confidential data.
Stage 2 · Built for you
We build OwnMind for your company and install it on infrastructure you control.
Confidential material belongs here, after your security review — never in the pilot.
Pricing
Fixed feeagreed at the fit check
Seven days on OwnMind's evaluation host, with fictional or sanitized material.
Annual licensequoted after the pilot
Your own build, installed in your rack or your cloud account after the pilot, and administered by your team.
Talk to us
Multiple deployments, unusual hardware, or requirements this page does not cover.
Each engagement is quoted for your company after the fit check. Your deployment runs on infrastructure you control: there is no OwnMind-operated inference tier and no per-token charge, because your questions never reach us. The pilot is the one exception. It runs on OwnMind's evaluation host, which is why it accepts sanitized material only.
What you can prove
Every answer carries the document name, the locator inside it, and the excerpt the model actually read. You can check the answer against the page.
Each administrative action on company knowledge appends a record naming the event, the pseudonymous actor, and the document involved.
Generation, embeddings, database, and API bind to loopback. What listens where is something your team can verify on the host itself.
Built to order
Everything above this line comes standard with a deployment. What follows is not part of the pilot or the standard build: each capability is scoped during your proposal and built into your deployment when your organization needs it. If one of them decides whether OwnMind fits, say so early.
SSO against the identity provider you already run, with access inside the application following your directory's groups and its joiners and leavers process — not only a gate at the edge.
SharePoint, Google Drive, Confluence and S3, so approving a source stops meaning re-uploading it by hand.
ACL-aware retrieval, so an answer can only draw on the documents the person asking is already cleared to read.
Air-gapped installation with signed update bundles, and SIEM export for teams whose logging is consolidated elsewhere.
Seven days, one company, up to five named users, and only fictional, public, or explicitly sanitized material. Remote access uses disclosed network and identity providers, and the evaluation is explicitly not zero-knowledge or end-to-end encrypted. If the pilot earns its place, we scope and build your deployment.