How it works

Plug in and go.

Unbox. Plug in. Ask. Data stays with you. Same Hatch OS from a phone — over your VPN.

1

Unbox

An encrypted cluster, already imaged for you. Hatch OS ready. House model path loaded. You do not assemble a stack.

2

Plug in

Ethernet to your network. Power on. You sign in first, then invite seats. No public cloud login. No SSH to ask a question.

3

Ask

Drop a PDF, or put files in the watched folder. Ask. Retrieval and answers stay on premises. Remote is your VPN — not a lab.

1

Arrive imaged

The cluster ships ready, customized to the fit we confirmed: seats, documents, knowledge base. Encryption is on. Models are local.

2

Join your network

Plug into the LAN. People reach Hatch OS. Work stays on your network — not a lab account.

3

You sign in, then invite

The first account is yours. You invite seats. Hatch OS is the login — ChatGPT-like, on your box.

4

Add documents

Upload in Hatch OS, or drop files into a watched folder. The house model can use the memo that should stay in the room.

5

Ask without sending it out

Chat on the cluster. The pass test: a non-technical person drops a PDF and asks. No SSH.

6

Check the status / connections page

See model state, disk encryption, and whether outbound is on. Proof for IT and counsel — not a sales paragraph.

Proof

Default-deny outbound.

The cluster does not call a frontier lab or a data company to answer. Egress starts off. Signed updates are optional and can be disabled. If IT wants a hole, that is a written choice — not a silent default.

We will not call this a certified air gap. We will say the intended posture: work stays on premises; the status page is how you see it. Remote access is people reaching this Hatch OS over your VPN — it does not mean the cluster uploads files to a lab.

Status / connectionsOn your network
Hatch OSReady
House modelOn your data
DiskEncrypted
OutboundDenied
Traffic to labsNone
Signed updatesDisabled by you

Remote

Same OS over your VPN.

The building is yours, not one desk. Traveling, you should use the same private AI — without pasting the memo into a lab because you left the floor.

What we mean

Secure access to Hatch OS on your cluster. Same models. Same documents. Same seats. Travel, phone, anywhere you already work.

What we do not mean

We do not host your files in a Hatch cloud. We do not send them to a frontier lab. We will not invent a VPN product name or claim a zero-attack-surface remote product.

What is confirmed later

How you get in from outside the office is confirmed when we image a unit — typically through the VPN you already trust. Pre-launch. We will be specific before you commit.

Backup and proof

You own the disk. You can show the page.

Backup

There is no Hatch cloud copy. Backup is the encrypted disk you own, or a copy you make of it. Unplug the cluster and the work stays with you.

What the status page shows

Hatch OS ready, disk lock, outbound on/off, update checks on/off. Plain language. Screenshot-friendly for IT.

What it is not

Not a public uptime badge. Not a SOC 2 report. Not a claim that nothing can leak if someone walks the hardware out of the room.