In short
Private AI for a company has three layers. The model: where your prompts are processed, on your own hardware or at a provider. The access: which keys, inboxes and business tools an AI agent can reach. The record: a log of what it did. A local model protects the first layer only. Protect all three by keeping keys out of plain text, giving each agent only what its job needs, requiring a person’s approval for changes, and logging every access.
Layer 1: the model, local or cloud
Modern Macs with Apple silicon can run capable open models locally, using tools such as Ollama or LM Studio. Nothing you type leaves the machine. The trade-offs are real: local models are smaller than the best cloud models, slower on long tasks, and someone has to set them up.
Cloud models are stronger and easier to use. On business plans, providers typically commit not to train on your data and offer retention controls. But the provider still processes whatever the agent sends, so choose the model to match how sensitive the work is.
- Public or internal material: a business plan of a cloud model is usually fine.
- Client-confidential or regulated material: prefer a local model, or keep the data out of the prompt.
- Anything in between: decide per task, and write the rule down.
Layer 2: the access, where most leaks happen
An agent is only as safe as what it can reach. Most agent setups put API keys and mailbox passwords in configuration files, share one key between several agents, and give that key more power than the task needs. A single instruction hidden in an email or a web page can then turn into a refund, a deleted file or a forwarded contract.
Four controls close most of that gap: keep credentials where agents cannot read them, grant each agent only the access its job needs, make any change wait for a person, and prefer read access wherever read is enough.
Layer 3: the record
When a client, an auditor or your own team asks “what did the AI see?”, you need an answer that is not a guess. That means a log of every key released, every mailbox read and every change proposed and approved, attributed to a specific agent and kept where you control it.
A sensible setup for a small company
You do not need a platform team. On a Mac, a small company can get to a safe setup in an afternoon:
- Move every API key out of .env and config files into a vault that releases keys per agent.
- Connect business tools (store, payments, shipping) through a local broker so agents get answers, not keys.
- Give email agents a connection that can read and draft, but never send.
- Put an approval step in front of anything that moves money or talks to customers.
- Pick the model per task: local for confidential work, a business cloud plan for the rest.
- Review the activity log weekly and remove access nobody used.
Checklist
Is your AI setup private?
- No API key or mailbox password sits in a plain-text file an agent can open.
- Each agent has its own, limited access, and you can revoke one without touching the others.
- Nothing that moves money, deletes data or contacts a customer happens without a person’s approval.
- You can list what each agent accessed last week.
- You know which model sees which kind of data, and it is written down.
How the MoltenRock apps put this into practice
Goldcote builds the MoltenRock suite for exactly this. It does not run the AI model; it protects the access and the record, on your Mac, with any model you choose.
Questions
Is a local model enough to make AI private?
It keeps your prompts on your machine, which is the first layer. It does nothing about which keys and systems the agent can reach, or whether anyone can later tell what it did. You need the access and record layers too.
Are cloud AI models unsafe for business?
Not by default. Business plans usually commit not to train on your data. The question is whether a given piece of data should leave your company at all; decide that per kind of data.
What is the single biggest risk?
Agents holding powerful credentials in plain text. Fix that first: it removes the most damage a mistake or an injected instruction can do.
Do we need a security team for this?
No. The controls above are settings, not projects. A small company can set them up in an afternoon and review them in minutes a week.
More guides
- A simple shadow-AI policy for small businesses
- AI and client confidentiality: a practical guide for law and accounting firms
- Human in the loop, explained: when an AI agent should ask first
- AI agents and money: a refunds and disputes playbook
- Letting AI change your Cloudflare safely
- Secrets hygiene for AI agents: OpenClaw, Hermes and your API keys
- AI email triage without send access
- Solutions →