Build a Privacy-First Local AI Workspace
Plan a privacy-first AI productivity startup from customer discovery through local-only desktop MVP architecture and engineering tasks.
privacy-first AI · local AI workspace · Tauri desktop app · AI productivity · startup planning
Last updated:
@ai-model:gemini-3.5-flash-lite I want to build a privacy-first AI productivity company from zero. Act as my operating partner over a long multi-step planning process. Start by defining the company thesis, ideal customer, initial product wedge, and the first 90-day roadmap. Keep it practical and concise, then ask me to continue with customer discovery.
As your operating partner, I'm glad to tackle this. Building a privacy-first AI productivity company is one of the most exciting and necessary challenges in tech right now, because many professionals and regulated companies are blocked from mainstream tools by data leakage and compliance risks. Let's lay down the foundational blueprint to kick off our multi-step planning process: ### 1. Company Thesis > **"AI capabilities shouldn't require trading corporate confidentiality or personal data sovereignty."** > > As foundation models commoditize, the ultimate defensibility won't be raw model intelligence; it will be **trusted execution**. By guaranteeing zero-data-retention, client-side encryption, and local-first or air-gapped inference routing, we unlock the massive, underserved market of knowledge workers bound by strict NDAs, IP protection, and regulatory frameworks (legal, medical, finance, defense-adjacent). ### 2. Ideal Customer Profile (ICP) * **Who:** Regulated knowledge workers and boutique firm partners (e.g., boutique law firms, wealth management practices, independent healthcare consultants, and deep-tech engineering teams). * **Pain Point:** They want to leverage AI for note-taking, document synthesis, and email drafting, but their compliance guidelines, client agreements, or internal security policies forbid feeding proprietary files into standard SaaS tools. * **Why Them:** They feel the productivity gap acutely, have high willingness to pay for software that solves compliance friction, and rely heavily on word-of-mouth networks. ### 3. Initial Product Wedge * **The Wedge:** A **Secure Local-First Document & Meeting Synthesizer**. * **What it does:** Runs an efficient small language model (SLM like Llama 3 or Mistral variants) directly on the user's local machine or via an encrypted, zero-knowledge cloud container. It transcribes local meetings, indexes confidential local PDFs, and drafts responses without shipping plaintext data to third-party model providers. ### 4. First 90-Day Roadmap * **Days 1–30: Validation & Architecture** * Finalize the core technical stack (local runner vs. zero-retention API wrapper). * Conduct 15–20 customer discovery interviews with our ICP to validate their exact compliance blockers. * **Days 31–60: Minimum Viable Product (MVP) Build** * Build a lightweight desktop wrapper/extension focusing on a single high-friction workflow (e.g., secure meeting debriefs and offline document querying). * Establish ironclad security positioning (open-source auditability or clear privacy guarantees). * **Days 61–90: Private Alpha & Feedback Loop** * Onboard 10 design partners from our discovery interviews. * Iterate on speed, output quality, and UI friction based on real-world usage. *** Would you like to continue with **Customer Discovery** to map out exactly how we'll run those initial 15–20 validation interviews with our ICP?
@ai-model:gemini-3.5-flash-lite Continue with customer discovery. Design a practical interview plan for 20 prospects: segments to recruit, outreach positioning, interview script, what signals would validate urgency, and what signals would tell us to pivot.
Let's get into customer discovery. The goal here is not to sell our solution, but to diagnose how painful today's compliance friction is and whether it causes lost billable hours or lost deals. Here is a practical, rigorous interview plan for our first 20 prospects. --- ### 1. Prospect Segments to Recruit (Target: 20 Interviews) We want to balance density within specific verticals to find patterns: * **Segment A (Legal / Compliance — 7 prospects):** Partners or associates at boutique law firms (IP, corporate M&A) who handle sensitive contracts daily. * **Segment B (Finance / Wealth Management — 7 prospects):** Independent financial advisors, wealth managers, or boutique M&A/private equity analysts dealing with non-public financial data. * **Segment C (Deep-Tech / Engineering Consultancies — 6 prospects):** Technical founders or engineering leads whose clients require strict NDA/IP separation. --- ### 2. Outreach Positioning *Never pitch software.* Position the call around research into workflow security and productivity bottlenecks. * **Subject Line:** Quick question on AI & client confidentiality at [Firm Name] * **Body Example:** > *"Hi [Name], I’m researching how boutique [law/wealth management] firms balance the productivity gains of AI with strict client confidentiality and NDA requirements. We're talking to 20 industry leaders to understand where current tools fail your compliance standards. Would you be open to a 20-minute chat next week? No sales pitch—just want to learn from your workflow challenges."* --- ### 3. Interview Script (20 Minutes) * **Context Setting (2 mins):** > *"Thanks for making time. We’re exploring how professionals with high confidentiality standards handle modern productivity tools. I want to learn about your actual workflows, not pitch you anything."* * **Current State & Behavior (5 mins):** > * "Walk me through how you currently handle tasks like synthesizing long client depositions, confidential financial reports, or drafting complex agreements." > * "Have you or anyone on your team tried using mainstream AI tools (like ChatGPT or Claude) for these tasks? What happened?" * **The Pain & Friction (5 mins):** > * "If you *did* use AI for sensitive documents, what specific guardrails or partner policies stopped you? Were they enforced by firm policy, client contracts, or your own peace of mind?" > * "Can you estimate how many hours a week your team spends on manual drafting or synthesis because you can't use standard automation?" * **Economic Impact & Workarounds (5 mins):** > * "What workarounds do you use today? (e.g., sanitizing text, using generic templates, or just doing it all manually)?" > * "If a tool guaranteed zero data retention and local execution, how would that change your team's output?" * **Wrap-up (3 mins):** > * "If we built a secure utility for this, would you be open to testing an early prototype with your team?" --- ### 4. Signals That Validate Urgency (Green Lights 🟢) We look for behavioral evidence, not polite compliments: * **"Hair-on-fire" compliance fear:** They can cite a specific client contract clause, data breach fear, or partner mandate that explicitly bans cloud-based AI. * **Active shadow IT or workarounds:** They admit team members are already pasting sensitive data into consumer AI tools under personal accounts because the productivity boost is too tempting to ignore (massive risk = massive urgency). * **Quantifiable time loss:** They report losing 5+ hours per week per person on tasks an LLM could solve if privacy wasn't a barrier. * **Immediate willingness to pilot:** They agree on the spot to be a design partner for a restricted internal alpha. --- ### 5. Signals That Tell Us to Pivot (Red Lights 🔴) We must be honest with ourselves if the market isn't there: * **Indifference to AI:** If they say, *"We don't really use AI or see the need for it in our workflows,"* the productivity pain isn't acute enough. * **Enterprise lock-in:** If they say, *"We are an enterprise Microsoft/Google shop, and our IT department is rolling out an internal secure copilot next month anyway,"* boutique wedge buyers will just wait for their existing stack to solve it. * **Regulatory apathy:** If compliance is treated as a check-the-box formality rather than a core business risk, they won't pay a premium for ironclad privacy. --- Would you like to move on to sketching out the **MVP Technical Architecture** (local SLMs vs. zero-retention wrappers) to see how we'd technically satisfy these prospects?
@ai-model:gemini-3.5-flash-lite Continue with MVP technical architecture. Compare three options for this privacy-first workspace copilot: local-only desktop app, encrypted cloud workspace with zero-retention model calls, and hybrid local-plus-cloud routing. Give a tradeoff matrix and recommend the first version.
Let's evaluate the technical architecture for our privacy-first copilot. The day-one architecture determines infrastructure costs, development speed, and how easily we can pass a strict security audit during customer discovery. Here is a comparison of the three architectural approaches, followed by a tradeoff matrix and our recommended first version. --- ### 1. Architectural Options Compared #### Option A: Local-Only Desktop App (Air-Gapped / Edge Execution) * **How it works:** A native desktop application (built with Tauri or Electron) bundles a runtime like [Ollama](wiki:Ollama) or Llamafile along with lightweight Small Language Models (SLMs) such as Llama 3 (8B) or Mistral 7B. Inference runs entirely on the user's CPU/GPU. * **Data Flow:** Zero data leaves the local machine. Files are indexed locally (e.g., via SQLite/LanceDB embedded vector stores). #### Option B: Encrypted Cloud Workspace with Zero-Retention API Calls * **How it works:** A web or desktop app where user documents are encrypted client-side using user-held keys (zero-knowledge architecture). When an AI request is made, text is decrypted in memory on an isolated, ephemeral cloud container running open-source models on rented GPUs (e.g., AWS Nitro Enclaves or dedicated instances with non-logging vendor agreements). * **Data Flow:** Data transits in ciphertext, hits a stateless container, runs inference, and vanishes immediately with no logging. #### Option C: Hybrid Local-Plus-Cloud Routing * **How it works:** The app dynamically classifies user prompts. Simple or highly sensitive queries (e.g., parsing an unredacted legal contract) are processed locally by an SLM. Complex reasoning or heavy synthesis tasks are automatically scrubbed of PII locally, then routed to a secure enterprise-grade cloud API (e.g., Anthropic or OpenAI enterprise tiers). * **Data Flow:** Split between local execution and encrypted cloud payloads. --- ### 2. Tradeoff Matrix --- ### 3. Recommended First Version: Option A (Local-Only Desktop App) For our **First 90-Day MVP**, we should strictly commit to **Option A: Local-Only Desktop App**. #### Why this wins for a zero-to-one startup: 1. **The "Zero-Trust" Shortcut:** During customer discovery, regulated prospects will immediately object to cloud architecture ("We need legal review for any new SaaS vendor handling data"). A local-only app completely bypasses vendor risk assessments and IT security sign-offs because *no data ever touches our servers*. 2. **Infinite Gross Margins on Day 1:** We don't have to raise capital just to pay for heavy GPU cloud inference bills while validating product-market fit. 3. **Product Focus:** It forces us to build an incredible, tightly scoped UX for document chunking, meeting transcription, and local context retrieval without getting bogged down in secure multi-tenant cloud infrastructure. #### The Strategic Pivot Path: Once we lock down design partners who love the local app but complain about hardware limits or context length on their local laptops, we can introduce an opt-in **Option B (Zero-Retention Cloud Workspace)** as an enterprise tier down the road. *** What would you like to plan next? We can explore **MVP Feature Scope & UX Design** for this desktop app, or dive straight into structuring our **Go-to-Market & Initial Design Partner Outreach**.
@ai-model:gemini-3.5-flash-lite Continue with MVP feature scope and UX. Define the smallest lovable workflow for the local-only desktop app, including onboarding, local file indexing, meeting transcript ingestion, document Q&A, draft generation, and privacy controls. Separate must-have, should-have, and later features.
Let's lock down the **MVP feature scope and UX** for our local-only desktop app. To make this product truly lovable (not just functional), we need to solve the friction of setting up local models while delivering an interface that feels as snappy and polished as a modern cloud SaaS tool (like Notion or Raycast), but running 100% offline. Here is the feature scope and UX roadmap categorized by priority: --- ### 1. Must-Have Features (Day 1 MVP Scope) *These are non-negotiable for our first private alpha release to design partners.* * **One-Click Local Model Setup (Onboarding):** * *UX:* Upon downloading the lightweight Tauri app, a clean setup wizard automatically checks the user's hardware (e.g., Apple Silicon vs. Windows/NVIDIA), downloads an optimized Small Language Model (like Llama 3 8B quantized), and runs a quick verification test. No command line required. * **Secure Local Folder Indexing:** * *UX:* A simple "Connect Workspace" button lets users select local folders (e.g., `/Client_Contracts/`) containing PDFs, Word docs, and markdown files. The app builds an embedded local vector index (using SQLite/LanceDB) entirely on device. * **Meeting Transcript Ingestion:** * *UX:* A drag-and-drop zone for raw audio/video files or text transcripts (.txt, .srt, .vtt) from local meeting recorders (like Otter exports or local OBS recordings). The app chunks and indexes the transcript instantly. * **Context-Aware Document Q&A & Synthesis:** * *UX:* A clean chat interface where users can query their indexed documents (`@ClientA contract terms`) and get precise, cited answers grounded strictly in local files without hitting external APIs. * **Draft Generation with Guardrails:** * *UX:* A side-by-side editor where users can highlight local notes or transcripts and prompt the model: *"Draft an executive summary email to the client based on this transcript."* * **Visible Privacy Status Bar:** * *UX:* A permanent, calming green badge in the corner of the app: `🟢 Air-Gapped / Zero Network Activity`, giving users instant psychological safety. --- ### 2. Should-Have Features (Fast Follows — Months 2–3) *Important for retention, but not strictly required to prove core value during initial user testing.* * **Local Audio Transcription Engine (Whisper.cpp):** * Allowing users to drop raw audio (.mp3, .wav) directly into the app and transcribing it locally via Whisper without needing third-party transcription tools. * **Template Library for Regulated Workflows:** * Pre-built, customizable prompt templates optimized for legal review checklists, financial disclosures, and technical spec audits. * **Document Diff / Redaction Helper:** * A tool that scans local drafts for accidental PII (names, SSNs, account numbers) before export or manual sharing. --- ### 3. Later Features (Post-MVP / Enterprise Tier) *Reserved for when we introduce hybrid or team-tier infrastructure.* * **Encrypted Peer-to-Peer Team Sync:** Allowing secure sharing of indexed workspaces between trusted colleagues via end-to-end encryption without central cloud storage. * **Opt-In Cloud Bursting:** Secure cloud fallback for power users whose hardware chokes on larger 70B models. * **Advanced Plugin Ecosystem:** Custom local WASM plugins for specialized industry compliance checkers. --- ### Summary Table: Feature Roadmap *** ### Suggested Next Steps 1. Map out the **Go-to-Market & Design Partner Strategy** to lock in our first 10 pilot users. 2. Outline the **Technical Stack & Architecture implementation steps** for the Tauri/Rust desktop client. What would you like to tackle next?
@ai-model:gemini-3.5-flash-lite Continue with go-to-market and design partner strategy. Build a 30-day plan to recruit 10 design partners, including channels, messaging angles, qualification criteria, incentives, onboarding process, weekly feedback cadence, and success metrics.
Let's create a rigorous, personal **30-day design-partner acquisition plan** to secure the first 10 pilot users. For a privacy-first product, trust is our primary asset. We aren't running broad ad campaigns; we are conducting a selective, high-trust concierge recruitment campaign to find professionals who feel the compliance bottleneck most acutely. --- ### Phase 1: Recruitment & Channels (Days 1–10) #### 1. Target Channels * **Warm Professional Networks:** Direct outreach to founder contacts, angel investors, and friendly startup lawyers or wealth managers who fit our ICP. * **Boutique Professional Communities:** Curated Slack/Discord groups, regional bar association tech committees, and independent financial advisor networks. * **LinkedIn Precision Outbound:** Targeting partners at 5–25 person boutique firms (IP law, M&A advisory, boutique wealth management) using the "Research & Feedback" angle. #### 2. Messaging Angles (The Hook) * **The Compliance Friction Angle:** *"We're building an air-gapped, zero-data-retention AI workspace specifically for firms bound by strict client confidentiality and NDAs. No cloud logging, no data exposure. Looking for 3 boutique partners to stress-test our early prototype."* #### 3. Strict Qualification Criteria (Who makes the cut?) To ensure high signal-to-noise, prospective design partners must meet three conditions: 1. **The Policy Hurdle:** They or their firm are currently restricted from using mainstream AI (ChatGPT, Claude enterprise-free tiers) due to client agreements or regulatory fears. 2. **The Volume Hurdle:** They personally spend 5+ hours per week reviewing contracts, synthesizing messy meeting transcripts, or drafting sensitive correspondence. 3. **Hardware Readiness:** They (or their team members) use modern developer or professional machines (Apple Silicon M1/M2/M3 or discrete NVIDIA GPUs) capable of running local models smoothly. --- ### Phase 2: Incentives & Onboarding (Days 11–15) #### 1. Design Partner Incentives * **Lifetime Early-Adopter Pricing / VIP Access:** Free lifetime access to the desktop app and future pro tiers in exchange for active participation. * **Direct Engineering Influence:** Their specific workflow bottlenecks become top-priority items on our weekly product sprint board. #### 2. Concierge Onboarding Process * **1-on-1 White-Glove Setup (30 Minutes):** We don't just send a download link. We jump on a video call, help them install the Tauri desktop app, verify their hardware compatibility, guide the automatic model download, and index their first test folder together. * **Baseline Workflow Mapping:** During the onboarding call, we identify *one* specific recurring task (e.g., "summarizing weekly client deposition transcripts") to test during their first week. --- ### Phase 3: Weekly Feedback Cadence & Operations (Days 16–30) #### 1. Structured Feedback Loop * **Weekly 15-Minute Syncs (Weeks 3 & 4):** A quick check-in covering three questions: 1. *What did you use the tool for this week, and where did it save you time?* 2. *Where did the model hallucinate, feel sluggish, or frustrate you?* 3. *What file formats or integrations are missing that blocked you from using it more?* * **Async Bug & Feature Reporting:** A dedicated, private Slack/Telegram channel or a lightweight in-app feedback widget for instant bug reporting. --- ### Phase 4: Success Metrics (How We Measure Victory at Day 30) We aren't tracking vanity signups. We measure true engagement: 1. **Retention / Active Usage:** At least 7 out of 10 design partners open and use the local app **3+ times per week** for real client work. 2. **Qualitative "Aha!" Moment:** At least 3 partners explicitly state: *"I couldn't have done [Task X] this fast without risking compliance violations."* 3. **Friction Identification:** Clear documentation of hardware limits, model latency bottlenecks, and UX friction points to fix before expanding the cohort. --- ### Next Steps & Action Plan With our thesis, customer discovery plan, technical architecture, MVP scope, and 30-day GTM strategy mapped out, our foundational zero-to-one blueprint is complete. Would you like to start executing on any specific pillar of this plan—such as drafting the exact LinkedIn outreach messages for our design partners, or breaking down the Tauri/Rust technical implementation steps?
@ai-model:gemini-3.5-flash-lite Draft the exact first outbound assets for recruiting design partners: a LinkedIn DM, a warm intro email, a follow-up email, a calendar invite description, and a short landing-page section. Keep them credible, non-hype, and privacy-focused.
Here are the concrete outbound and conversion assets for recruiting our first 10 design partners. Each asset uses a tone of calm competence, respects their professional diligence, and avoids hype language. --- ### 1. LinkedIn DM (Short & Respectful) *Use this for direct, warm-to-cold outreach to boutique firm partners and consultants.* > "Hi [Name], I noticed your work in [Practice Area / Industry] at [Firm Name]. We’re currently developing a local-first, air-gapped AI workspace built specifically for firms bound by strict client confidentiality and NDAs. > > Because cloud AI tools present compliance hurdles for sensitive data, we’re running a small private alpha with 10 boutique partners to stress-test an entirely offline document and meeting synthesizer. > > Would you be open to a brief 20-minute feedback chat next week to see if it fits your workflow guardrails? No sales pitch—just want to learn from your security requirements." --- ### 2. Warm Intro Email *Use this when reaching out via email or when an investor/mutual contact makes an introduction.* > **Subject:** Research on AI productivity & client confidentiality at [Firm Name] > > Hi [Name], > > [Mutual Connection / "I came across your profile via..."] suggested I reach out. > > We are building an air-gapped AI productivity workspace designed for professionals who want the synthesis capabilities of modern LLMs without feeding proprietary client files or transcripts into cloud models. Everything runs locally on device with zero data retention. > > We’re speaking with 20 leaders in [legal / wealth management / advisory] to understand how your firm navigates AI compliance and what bottlenecks you face. > > Would you have 20 minutes next Tuesday or Thursday for a quick conversation? I’d love to get your perspective on our early prototype guardrails. > > Best, > [Your Name] --- ### 3. Follow-Up Email (4 Days Later) *Sent as a gentle, low-pressure bump.* > **Subject:** Re: Research on AI productivity & client confidentiality at [Firm Name] > > Hi [Name], > > I know how demanding client schedules are, so I'll keep this brief. > > We’ve finalized our private alpha cohort with 7 boutique firms and have 3 spots remaining for our initial design partner group. If confidentiality guardrails have kept your team from adopting AI tools for drafting or document review, I'd still love your feedback. > > If timing doesn't work right now, no worries at all. If you're open to a 20-minute chat, you can grab a time that suits you here: [Calendar Link]. > > Best, > [Your Name] --- ### 4. Calendar Invite Description *Set expectations clearly so they arrive prepared for an advisory session rather than a high-pressure sales pitch.* > **Title:** 20-Minute Advisory Chat: Secure AI Workflows & Confidentiality > > **Description:** > Thanks for making time to chat! > > **Goal of this call:** > To learn how [Firm Name] balances the productivity gains of AI with strict client confidentiality and NDA compliance, and to get your candid feedback on our local-first desktop prototype. > > **Agenda (20 Mins):** > 1. Current workflow bottlenecks in document review & synthesis (5 mins) > 2. Security, compliance, and partner policy guardrails you deal with (5 mins) > 3. Quick walk-through of our air-gapped local app approach for your feedback (7 mins) > 4. Next steps & private alpha pilot fit (3 mins) --- ### 5. Short Landing-Page Section *Use this for a private, password-protected waitlist page shared via direct link.* > **[H1] AI Productivity Without Compromising Client Confidentiality.** > **[Subheadline]** Standard AI tools require trusting cloud servers with sensitive files and client data. We are building an air-gapped, local-first workspace for regulated professionals. Zero cloud logging. Zero data leakage. Full local sovereignty. > > **[Bullet Points]** > * **100% Offline Inference:** Runs locally on your machine using optimized small language models. > * **Secure Local Indexing:** Query local PDFs, contracts, and transcripts without data transit. > * **Designed for Boutique Firms:** Built specifically for practices bound by strict NDAs and compliance standards. > > **[Call to Action Button]** Request Private Alpha Access --- ### Suggested Next Steps 1. **Interactive Review:** Would you like to test these out by simulating a prospect persona response, or shall we map out the **Product Requirements Document (PRD)** for our Tauri desktop client wrapper? 2. **Follow-up Prompt:** If you'd like to adjust the tone or focus of these messages for a specific legal or financial sub-segment, let me know!
@ai-model:gemini-3.5-flash-lite Continue by mapping out the Product Requirements Document (PRD) for the local-only Tauri desktop client wrapper. Include target users, core jobs-to-be-done, user stories, functional requirements, non-functional privacy/security requirements, acceptance criteria, MVP milestones, and explicit out-of-scope items.
Let's draft a comprehensive **Product Requirements Document (PRD)** for our privacy-first Tauri desktop client wrapper. This document is the engineering North Star for the 30-day MVP build. --- # Product Requirements Document (PRD): Privacy-First Local AI Workspace (Tauri MVP) ## 1. Document Metadata * **Product Name:** Project Citadel (Working Title) * **Target Release:** 30-Day MVP / Private Alpha * **Author:** Operating Partner & Engineering Lead * **Status:** Draft / Approved for Sprint 1 --- ## 2. Target Users & Persona * **Primary Persona:** Boutique firm partners, senior associates, and independent consultants handling sensitive client files, legal contracts, or confidential financial data who are barred from using standard cloud AI tools due to NDA and compliance restrictions. --- ## 3. Core Jobs-To-Be-Done (JTBD) 1. *"When I have a 50-page confidential client contract, I want to query specific clauses locally so I can find answers instantly without leaking proprietary text to a cloud server."* 2. *"When I finish a sensitive client deposition or advisory call, I want to drop the raw audio or transcript into a private tool and generate an executive summary draft without data leaving my laptop."* --- ## 4. User Stories * **US-1 (Onboarding):** As a user, I want the app to automatically detect my hardware and download a secure local language model with one click, so I don't have to configure command-line runtimes. * **US-2 (Folder Indexing):** As a user, I want to select a local folder of PDF/docx files so the app can securely index them into an offline vector database. * **US-3 (Document Q&A):** As a user, I want to chat with my indexed documents and receive precise, cited answers grounded entirely in local files. * **US-4 (Draft Generation):** As a user, I want to highlight local notes or transcripts and prompt the model to draft an email or summary. * **US-5 (Privacy Assurance):** As a user, I want visual confirmation that my app is completely air-gapped so I have absolute peace of mind regarding data sovereignty. --- ## 5. Functional Requirements * **FR-1: Cross-Platform Desktop Shell:** Built using Tauri (Rust backend, web frontend) for lightweight resource usage and fast startup times. * **FR-2: Local Inference Runtime Integration:** Bundled or auto-managed local model runner (e.g., Ollama or embedded llama.cpp) supporting quantized models (Llama 3 8B / Mistral 7B). * **FR-3: Local File Parser & Vector Store:** * Support parsing `.pdf`, `.docx`, `.txt`, and `.md` files. * Embedded local vector storage (SQLite + SQLite-VSS or LanceDB) stored locally in the user's application support directory. * **FR-4: Chat & Prompt Interface:** Clean, split-pane chat interface supporting markdown output, source document citations, and prompt history saved locally. * **FR-5: Air-Gapped Status Indicator:** Persistent UI badge displaying network isolation status (`🟢 Air-Gapped`). --- ## 6. Non-Functional Privacy & Security Requirements * **NFR-1: Zero Telemetry & Network Isolation:** The application executable must operate 100% offline post-model download. Outbound network calls are strictly restricted to local model registry downloads (optional user action) and blocked otherwise. * **NFR-2: Local-Only Data Persistence:** All chat histories, embeddings, and vector indices must reside exclusively in encrypted or sandboxed local storage directories (`~/Library/Application Support/...` or equivalent OS paths). No database sync to external cloud buckets. * **NFR-3: Memory Hygiene:** Sensitive prompt strings and decrypted document chunks must be cleared from process memory immediately upon session termination or app close. --- ## 7. Acceptance Criteria (MVP Gate) * [ ] Application successfully installs on macOS (Apple Silicon) and Windows 11 via a signed installer. * [ ] One-click setup downloads and verifies Llama 3 8B within 3 minutes on standard hardware. * [ ] User can index a folder of 20 PDFs (approx. 50 pages each) locally without crashing or exceeding 4GB RAM utilization. * [ ] User can ask a targeted question about the documents and receive a grounded answer with inline citations in under 5 seconds. * [ ] Network monitor verification confirms **zero outgoing packets** to third-party endpoints during active chat and indexing operations. --- ## 8. Explicit Out-of-Scope (Deferred to Post-MVP) * Cloud-based fallback or hybrid routing to OpenAI/Anthropic APIs. * Real-time audio recording and transcription (Whisper.cpp integration deferred to Fast Follow). * Multi-user P2P workspace sharing or encrypted cloud sync. * Windows on ARM (WOA) optimization. --- ### Suggested Next Steps With our PRD complete, we can begin sketching the initial **UI Wireframe/Architecture** or start mapping out the **Sprint 1 Engineering Tasks** for the Tauri/Rust core. What would you like to build or define next?
@ai-model:gemini-3.5-flash-lite Continue with Sprint 1 engineering tasks for the local-only Tauri/Rust desktop MVP. Break the work into concrete tickets for app shell, local model setup, document parsing, indexing, chat UI, citations, privacy controls, packaging, QA, and measurement. Include dependencies, risks, and acceptance checks for each workstream.
Here is the complete **Sprint 1 engineering task breakdown** for our 30-day MVP. The work is split into 10 clearly separated workstreams, with dependencies, technical risks, and verifiable acceptance criteria for each ticket. --- # Sprint 1 Engineering Backlog: Local-Only Tauri Desktop MVP ## Workstream 1: App Shell & Tauri/Rust Core Setup * **Ticket ID:** `ENG-01` * **Objective:** Initialize the cross-platform Tauri (Rust + TypeScript/React) project repository with secure inter-process communication (IPC) boundaries and sandboxed file system access. * **Dependencies:** None (Greenfield repo initialization). * **Key Tasks:** * Initialize Tauri 2.x project with React and Vite template. * Configure `tauri.conf.json` with strict CSP (Content Security Policy) blocking all external network fetch/XHR requests except explicit localhost bindings. * Establish Rust backend state management for local process tracking. * **Risks:** Tauri permission scopes allowing accidental file leakage or loose CSP. * **Acceptance Checks:** * [ ] `cargo tauri build` compiles clean on macOS (Apple Silicon) and Windows 11. * [ ] Network inspector confirms zero external domain sockets opened upon launch. --- ## Workstream 2: Local Model Manager & Runtime Integration * **Ticket ID:** `ENG-02` * **Objective:** Bundle or programmatically manage a local inference runtime (e.g., embedded `llama.cpp` via Rust bindings or automated local Ollama sidecar management) supporting quantized GGUF models. * **Dependencies:** `ENG-01` (App Shell). * **Key Tasks:** * Implement Rust sidecar manager to spawn/terminate local inference binary. * Create a model download utility with SHA-256 verification and resume support for Llama 3 8B Instruct (GGUF). * Expose local `/v1/chat/completions` or direct Rust FFI inference bridge to frontend. * **Risks:** Platform-specific binary compilation issues (Metal vs. CUDA vs. CPU fallback). * **Acceptance Checks:** * [ ] App successfully verifies, downloads, and loads Llama 3 8B GGUF. * [ ] Inference generates first-token response within 2 seconds locally on M-series Apple Silicon. --- ## Workstream 3: Local File Parsing Pipeline * **Ticket ID:** `ENG-03` * **Objective:** Build a robust, offline-first document parsing engine capable of extracting clean text and structural metadata from `.pdf`, `.docx`, `.txt`, and `.md` files. * **Dependencies:** `ENG-01`. * **Key Tasks:** * Integrate Rust-native PDF parser (`lopdf` or `pdf-extract`) and docx extractor. * Implement text chunking with configurable overlap (e.g., 512-token chunks with 64-token overlap) preserving paragraph boundaries. * Handle malformed or scanned PDFs gracefully with fallback warnings. * **Risks:** Memory bloat when parsing large multi-hundred-page legal PDFs. * **Acceptance Checks:** * [ ] Parses a 100-page `.docx` or `.pdf` file in under 3 seconds without exceeding 500MB RAM spike. * [ ] Preserves clean paragraph breaks and table text structure in chunk output. --- ## Workstream 4: Local Vector Database & Indexing Engine * **Ticket ID:** `ENG-04` * **Objective:** Embed text chunks using a lightweight local embedding model (e.g., `all-MiniLM-L6-v2` via ONNX Runtime or Candle) and persist vectors in a local SQLite + `sqlite-vss` or LanceDB store. * **Dependencies:** `ENG-03` (File Parser). * **Key Tasks:** * Integrate Rust embedding runner (`candle-nn` or ONNX). * Initialize local vector store in `~/Library/Application Support/ProjectCitadel/vectors.db`. * Implement incremental folder indexing (skip already hashed/unchanged files). * **Risks:** Slow CPU embedding generation on older Windows machines without AVX2 instructions. * **Acceptance Checks:** * [ ] Successfully indexes 50 test documents (approx. 500 pages total) in under 45 seconds. * [ ] Vector similarity search returns top-5 relevant chunks in <50ms. --- ## Workstream 5: Chat UI & Prompt Workspace * **Ticket ID:** `ENG-05` * **Objective:** Build a responsive, distraction-free chat interface in React with Markdown rendering, syntax highlighting, and local conversation history persistence. * **Dependencies:** `ENG-01`, `ENG-02`. * **Key Tasks:** * Develop split-pane layout (left sidebar for file folders and chat history, right main pane for active chat). * Implement streaming response UI with auto-scroll and markdown rendering. * Save conversation sessions to local SQLite store (`chats.db`). * **Risks:** UI sluggishness during rapid streaming token rendering. * **Acceptance Checks:** * [ ] Smooth 60fps streaming token display during model generation. * [ ] Conversations persist across application restarts. --- ## Workstream 6: Citation & Source Grounding Engine * **Ticket ID:** `ENG-06` * **Objective:** Implement retrieval-augmented generation (RAG) context assembly and UI citation badges linking model answers back to specific local files and page numbers. * **Dependencies:** `ENG-04` (Vector DB), `ENG-05` (Chat UI). * **Key Tasks:** * Query vector store for top-k matching chunks on user prompt submission. * Construct prompt context with explicit source file markers (`[Source: filename.pdf, Page X]`). * Render interactive citation cards in UI that preview source snippet on hover/click. * **Risks:** Hallucinated citations or context window overflow with overly broad chunk retrieval. * **Acceptance Checks:** * [ ] 100% of factual answers derived from indexed files include verifiable source badges. * [ ] Clicking a citation opens the local file excerpt drawer. --- ## Workstream 7: Privacy Status Bar & Network Sandbox * **Ticket ID:** `ENG-07` * **Objective:** Build a persistent privacy monitoring widget and enforce strict OS-level network isolation verification. * **Dependencies:** `ENG-01`. * **Key Tasks:** * Create prominent header/footer status bar indicating `🟢 Air-Gapped / Zero Network Activity`. * Implement active socket monitor in Rust background thread that logs outbound connection attempts (alerting if non-localhost traffic is detected). * Add manual "Kill Switch" button that instantly halts all local inference and clears temporary caches. * **Risks:** False positives from local loopback address bindings (`127.0.0.1`). * **Acceptance Checks:** * [ ] Status indicator accurately reflects network state. * [ ] Automated test suite verifies zero external DNS lookups or HTTP requests during core operations. --- ## Workstream 8: Packaging & Auto-Updater (Local First) * **Ticket ID:** `ENG-08` * **Objective:** Configure Tauri bundler to produce signed macOS `.app`/`.dmg` and Windows `.msi` installers without relying on external cloud telemetry analytics. * **Dependencies:** `ENG-01` through `ENG-07`. * **Key Tasks:** * Set up code signing certificates for macOS Developer ID and Windows Authenticode. * Configure GitHub Releases or local network manifest for zero-tracking updates. * Write clean `README.md` installation instructions for alpha testers. * **Risks:** Apple Gatekeeper or Windows SmartScreen blocking unsigned/new binaries. * **Acceptance Checks:** * [ ] Clean installation on fresh macOS and Windows VMs without OS security blocks. * [ ] App launches into functional onboarding wizard on first boot. --- ## Workstream 9: QA & Performance Benchmarking * **Ticket ID:** `ENG-09` * **Objective:** Establish automated integration tests for document chunking, vector search accuracy, and memory leak detection. * **Dependencies:** `ENG-03`, `ENG-04`, `ENG-06`. * **Key Tasks:** * Write Rust unit tests for PDF extraction and chunking edge cases. * Perform end-to-end load test with a 200-document repository to measure RAM stability. * Validate zero crash rates during abrupt app termination. * **Risks:** Edge cases in PDF text encoding (e.g., custom font encodings). * **Acceptance Checks:** * [ ] 90%+ unit test coverage on core parsing and retrieval Rust modules. * [ ] Memory consumption remains stable under 4GB RAM during prolonged Q&A sessions. --- ## Workstream 10: Measurement & Alpha Telemetry (Opt-In / Local) * **Ticket ID:** `ENG-10` * **Objective:** Implement a local-only usage logger that exports anonymized performance metrics (e.g., query latency, token generation speed, index build time) to a local JSON file for alpha testers to optionally share. * **Dependencies:** `ENG-05`, `ENG-07`. * **Key Tasks:** * Build local metrics collector capturing latency percentiles and error rates. * Create "Export Diagnostics" button in settings that bundles logs into a local zip file for manual review by engineering. * Ensure zero automatic telemetry transmission over the internet. * **Risks:** Testers forgetting to export logs or encountering cryptic panic traces. * **Acceptance Checks:** * [ ] Diagnostics export generates a clean JSON summary of app performance without leaking document text or prompt contents. --- ### Suggested Next Steps With our Sprint 1 engineering backlog fully mapped out, we are ready to assign tasks or dive into the architectural implementation of **Ticket `ENG-01` (App Shell & Tauri/Rust Core Setup)** or **`ENG-03` (Local File Parsing Pipeline)**. Would you like to start reviewing the Tauri project scaffolding configuration or dive into the Rust parser implementation?
@ai-model:gemini-3.5-flash-lite Continue by reviewing the Tauri project scaffolding configuration for ENG-01. Specify the recommended repository structure, tauri.conf.json security settings, CSP/network restrictions, Rust command boundaries, local filesystem permissions, build scripts, and the first smoke tests we should write before implementing features.
To create a robust, locked-down foundation for **Project Citadel** under **Ticket `ENG-01`**, we need to configure our Tauri 2.x project scaffolding with zero-trust IPC boundaries, strict Content Security Policies (CSP), explicit filesystem capability scopes, and automated smoke tests. Since our core thesis is absolute data privacy and zero network leakage, our configuration must actively clamp down on default Tauri permissive settings. --- ### 1. Recommended Repository Structure A clean, modular layout separates our React/TypeScript frontend from the secure Rust backend and Tauri configuration: --- ### 2. `tauri.conf.json` Security Settings & CSP In Tauri v2, security policies are heavily fortified. We configure our app window with a strict Content Security Policy (CSP) that blocks all external network fetches, WebSockets, and CDN scripts, allowing only local loopback communication (`[link removed]` or Tauri's custom asset protocol). > **Security Note on `connect-src`:** The CSP explicitly restricts connections to `self` and local loopback port `11434` (reserved for local sidecar runtimes like Ollama or custom local inference servers). Any attempt by malicious frontend dependencies to phone home to external APIs will be blocked instantly by the browser engine. --- ### 3. Tauri v2 Capability Scopes (Filesystem Permissions) In Tauri v2, file system access is governed by explicit capability files inside `src-tauri/capabilities/`. We restrict the app's file reading capabilities to explicit user-selected folders, preventing arbitrary system traversal. --- ### 4. Rust Command Boundaries & State Management We establish clean IPC boundaries in Rust (`src-tauri/src/lib.rs`) ensuring the frontend can only invoke explicitly registered commands. --- ### 5. Build Scripts & Package Configuration --- ### 6. Smoke Tests Before Feature Implementation Before moving on to local model integration (`ENG-02`) or file parsing (`ENG-03`), we should implement the following smoke tests to verify security and scaffolding integrity: 1. **CSP Block Test (Frontend Smoke Test):** * Write a quick Playwright or manual test attempting `fetch('[link removed]')` from the React app. * **Expected Result:** The browser console must throw a CSP violation error, rejecting the outbound request. 2. **Filesystem Scope Enforcement Test (Backend Smoke Test):** * Invoke a file read command via Tauri targeting `/etc/passwd` (on Unix) or `C:\Windows\System32\drivers\etc\hosts` outside allowed scopes. * **Expected Result:** The Tauri filesystem plugin must return a permission denied error. 3. **Air-Gap Mock Test:** * Verify that Tauri builds without network dependencies during offline compilation (`cargo build --offline`). --- ### Suggested Next Steps Would you like to move forward with setting up **Ticket `ENG-02` (Local Model Manager & Runtime Integration)** to handle local GGUF/Ollama sidecar startup, or refine the Tauri capabilities further?
Related questions you can ask
- Search for Tauri project scaffolding best practices
- Explain the importance of strict CSP in Tauri projects
- Find Rust libraries for secure IPC
- List common security pitfalls in Tauri applications
- Compare local inference runtimes for Rust
- Help me understand the implications of capability scopes in Tauri