Project files and code
All source code, spreadsheets, text documents, and configuration files remain in their original directories on your computer. The Harness only reads files in folders you explicitly open.
Data architecture
TritonAI Harness uses a local-first architecture. Your project files, transcripts, and credentials stay on your computer. This statement explains what data stays local, what passes through the gateway, and how UC policies apply.
Unlike centralized web chat interfaces, the Harness does not retain your work on campus servers. You keep custody of your local files and project history.
Local storage
The Harness stores operational data locally within your user account rather than on central servers.
All source code, spreadsheets, text documents, and configuration files remain in their original directories on your computer. The Harness only reads files in folders you explicitly open.
Task transcripts, agent execution steps, and interaction histories are written directly to your local application directory. They are not stored on central campus servers.
Persistent notes, context summaries, and reference instructions are saved as local Markdown files on your workstation. No cloud indexing or external training takes place.
Network transit
Communication between your workstation and TritonAI infrastructure is limited to active model requests and operational telemetry.
When an agent turn executes, only the prompt text and specific file snippets needed for that turn travel across encrypted HTTPS to the TritonAI Gateway.
Campus on-premises models hosted on campus infrastructure process requests with zero data retention and no model training. Your prompts are discarded after generating the response.
The Harness maintains an empty cloud fallback list by default. If an on-premises model is temporarily unavailable, the error is surfaced immediately. Private campus context is never silently redirected to external cloud providers.
The Gateway logs request timestamps, model identifiers, token counts, and account identifiers to monitor platform availability, manage quotas, and apply recharge billing where applicable.
The Gateway does not record the text content of your local files, shell command outputs, or conversation transcripts in its telemetry logs.
Credential boundaries
TritonAI Harness uses host-managed authentication to isolate credentials from language models.
OAuth tokens for GitHub, Google Workspace, and Microsoft 365 reside in the local host secret store. Tokens are never passed into model prompt context.
The Harness application process makes authorized API calls directly. The AI agent only proposes structured parameters for each action.
Write operations for email and calendar default to draft mode. External changes require explicit human confirmation before sending or publishing.
Each plugin can be toggled on or off in Settings. Disabling access immediately revokes tools before the next agent turn.
Policy compliance
Use of the Harness must align with University of California Electronic Information Security Policy (IS-3).
TritonAI Harness is approved for UC information classified as Protection Level 1 (Public), Protection Level 2 (Internal), and Protection Level 3 (Sensitive) within approved campus setups.
Because project files and transcripts reside on your local computer, your workstation must meet UC San Diego minimum security standards, including active disk encryption (FileVault on macOS, BitLocker on Windows).
Protection Level 4 (P4) data is strictly prohibited in TritonAI Harness. This includes electronic protected health information subject to HIPAA, credit card numbers subject to PCI DSS, and high-consequence regulatory data.
For health system patient-care workflows, consult the approved clinical AI services available through the UC San Diego Health Pulse portal.
User control
Because session data is stored locally, you maintain complete control over data removal.
You can delete past task transcripts, remove cached files, or clear memory entries at any time by removing them from your local directory or clearing history within the application interface. Deletion is instantaneous and permanent.
To revoke Microsoft 365 access, use the Disconnect button in Settings under Plugins, or revoke permissions directly in your Microsoft 365 account security settings.
Governance contact
For questions regarding TritonAI data governance, security assessments, or approved use cases, contact the service team.