Where your data lives.
Most AI vendors answer that question with a picture of their data center. Ours starts with a shelf in your office.
This page is written for the person who has to sign off — your IT lead, your compliance officer, your attorney. It says where each kind of information sits, what crosses the internet and what never does, and what stays yours if we stop working together.
Private where it matters. Audited everywhere.
Primare runs on two layers, each doing the job it's built for.
Your appliance.
The sensitive things — customer records, files, your House Model — live on hardware you own, in your building. Single-tenant: no other business on the box, no pooled data. There's no per-use meter either; local inference doesn't bill by the word.
Your platform.
The everyday tools — phones, texting, reviews, scheduling — run on a managed platform audited to the standards your IT or compliance reviewer will ask about: SOC 2 Type II attested, ISO 27001 certified, encrypted in transit and at rest, hosted in the U.S., independently penetration-tested.
Where the line falls.
A phone call has to cross a carrier. An email has to cross a mail server. Anyone who tells you otherwise is selling you something. Here is exactly where the line falls.
Stays on your appliance.
The customer records, notes, and documents it reads. Your House Model and everything used to train it. The reasoning itself — every draft, summary, and decision the AI produces is computed on your hardware, in your building.
Crosses the platform.
Phone calls and text messages, because carriers carry them. Outbound email. Your calendar, your pipeline, and the conversation history your team works from day to day. Review-site replies, because the review lives on the review site.
We would rather show you where the line actually falls than claim a line that isn't there.
Nothing you type trains someone else's model.
The models run on your appliance. There is no outside model vendor in the path — nothing is handed to a third-party AI service to be processed, retained, reviewed by their staff, or folded into their next training run.
Precisely: Primare does not send prompts or retrieved records from the on-site inference layer to any outside model service. The communications platform still processes what it must to deliver calls, texts, and scheduling.
This is the part that is hard to retrofit. On the consumer AI tiers most small businesses use, the vendor's own policy reserves the right to learn from what you send. Once that has been happening for a year, it cannot be taken back. Running the model on your own hardware is what makes the question moot rather than a matter of trust.
Who can reach the box.
You, physically.
It is in your building, behind your door, on your power. Physical custody is simply yours; there is nothing for us to administer on your behalf.
Us, under contract.
We maintain, monitor, and tune it over an authenticated, logged remote connection scoped to that work. It is ours to use for keeping your system healthy, and yours to revoke.
What you keep is not a promise. It's a receipt.
The hardware is yours; you bought it. Your data is yours, and we hand it back in a portable format rather than holding it as leverage. Your House Model, and the work that went into it, is yours.
What is delivered by subscription is the platform layer and our maintenance: the phones, the texting, the scheduling, and the work of keeping the system current as the models improve. Those are services, and services end when a contract ends.
We will walk you through exactly which parts of your operation lean on which layer before you sign, not after. An ownership pitch that gets vague at this question isn't one.
Send us your security questionnaire.
We answer it. A written architecture and controls packet — data flows, retention, access, subprocessors — is available for your reviewers on request.
For healthcare, Primare signs a Business Associate Agreement, and patient information is processed on your on-site appliance. For any regulated engagement, a data processing agreement is available.
If your reviewer needs something this page doesn't cover, ask on the Discovery Call and we will put it in writing.
Everything runs somewhere audited. Anything sensitive runs on hardware you own.
The reviewer's questions have answers. Let's go through them.
Bring your IT lead or your compliance officer to the call. Thirty minutes, no pitch deck, and a straight answer on every question they have.
Book a 30-minute Discovery Call →