04 / deployments

Institutional control

Installed where authority lives.

Aetheria operates inside the institution's identity, data, security, policy, infrastructure, and recovery boundary—not as an opaque shared control plane.

Supported profiles

Two complete operating forms.

Each profile includes clean installation, configuration, durable storage, backup and restore, upgrade, rollback, repair, removal, and an explicit offline boundary.

Profile 01

Windows standalone workstation

A complete local system for a governed operator environment on an independently managed computer.

Access
https://aetheria.localhost
Identity
Local accounts and MFA
Storage
Encrypted durable store
Recovery
Local backup and restore
Network
Fully useful offline
Owner
Workstation administrator
Profile 02

Private Ubuntu LAN appliance

An organizational deployment serving governed users across a controlled private network.

Access
TLS-protected private edge
Identity
Role-based institutional access
Storage
Encrypted durable store
Recovery
Off-host backup and restore
Network
Fully useful offline on LAN
Owner
Institutional administrator

Deployment topology

Local control with explicit external reach.

Local users reach Aetheria through the institution's controlled edge. Provider and connector access is configured, credentialed, and observable. Local workflows never switch silently to a public provider.

Institutional usersApproved roles · managed devices
Aetheria applianceGovernance · Gateway · evidence
Declared railsLocal systems · approved providers

Operational ownership

The deployment carries its own recovery path.

A supported installation remains operable beyond first boot. Administration, provider controls, backup, restore, upgrade, rollback, health, evidence export, and removal are part of the deployed system.

Identity

Authority starts with the actor

Accounts, roles, delegations, and revocation remain inside the institutional trust boundary.

Data

Sources retain provenance

Ingestion, OCR, retrieval, citations, holds, retention, and redaction preserve their source relationships.

Providers

Keys stay under control

Approved model providers use declared credentials and network paths without hidden fallback.

Evidence

Receipts remain portable

Governance records and assurance evidence survive the operational workflow that produced them.

Recovery

Unknown state remains actionable

Reconciliation, rollback, repair, restore, and revocation are explicit operating procedures.

Removal

Exit is part of support

The institution retains a defined path to export, remove, and verify the installed system.

Municipal operations

Council Memory.

Municipal records become a governed working memory: source-grounded, permission-aware, citation-first, and subordinate to the people responsible for adoption and action.

  1. 01Ingest the record

    Documents, scans, minutes, policies, procedures, and attachments enter with provenance.

  2. 02Extract and classify

    OCR and document processing preserve page and source relationships.

  3. 03Retrieve exact support

    Answers carry citations, conflicts, and abstention when the record does not support a claim.

  4. 04Route human review

    The responsible municipal role resolves policy, records, legal, and operational authority.

  5. 05Adopt through a governed rail

    Approved work enters the authorized workflow with a governance receipt.

Governed domains

Different institutions. The same execution discipline.

Each domain brings distinct policy, evidence, confidentiality, retention, and human- authority requirements onto the same Aetheria control spine.

01

Municipal Operations

Records, policy, minutes, workflow, and accountable adoption.

Deployment boundary
03

Healthcare

Governed advisory and operations with licensed human authority preserved.

Deployment boundary
04

Legal

Document, research, and workflow support under attorney and client authority.

Deployment boundary

Consequential action requires accountable authority.

Put a governed boundary between intent and effect.