Model configuration
Which engines this deployment may route to, and where their data goes.
Only approved models are routed to
Configured models (3)
- (example) third-party cloud modelnot approved
Not approved · —
Data leaves the perimeter for this engine. Confirm this is acceptable for the data classification it processes before enabling it.
Placeholder showing how an unapproved model is represented. Nothing routes to an unapproved model.
updated 2026-09-29 10:21:42
- Asterxa engine (agent brain)approved
Asterxa · Agent roles: extraction, normalisation, policy checks, briefings
Data leaves the perimeter for this engine. Confirm this is acceptable for the data classification it processes before enabling it.
Configured per deployment via ASTERXA_API_KEY, read server-side only. When no key is present every role degrades to a visibly-labelled sandbox run.
updated 2026-09-29 10:21:42
- Deterministic local analysersapprovedlocal only
In-process · Sandbox fallback: text heuristics, OCR stub, transcript segments
Data does not leave the perimeter.
No model. Deterministic and fully local. All sandbox agent runs are attributed to this, never presented as model output.
updated 2026-09-29 10:21:42
Where data is STORED versus where it is PROCESSED
These are two different questions, and the earlier UI merged them
- Asterxa engine (agent brain)leaves the perimeterStored: Not retained by this applicationProcessed: EXTERNAL — the Asterxa service (lite.asterxa.ai)Basis: Explicit operator configuration via ASTERXA_API_KEYPermitted data classes: public, internal
Routing a role to Asterxa SENDS the target text to an external service. Because that crosses the perimeter, only public and internal material may be routed to it in this configuration. Restricted or sensitive case content must NOT be sent: use the deterministic local analysers instead. A workspace's 'In-country' setting governs STORAGE and does not, by itself, authorise external processing.
- Deterministic local analysersstays in-countryStored: In-country — the deployed hostProcessed: In-country — the deployed hostBasis: Built-in, no external callPermitted data classes: public, internal, restricted, sensitive
No model and no network egress. Not a model — accurate but deterministic, and labelled as such everywhere.
- This application (record storage)stays in-countryStored: In-country — the deployed hostProcessed: In-country — the deployed hostBasis: Workspace data-residency settingPermitted data classes: public, internal, restricted, sensitive
Records and evidence stay on the deployed host. This is what 'In-country' on a workspace refers to.
A workspace set to 'In-country' governs storage. It does not, by itself, authorise processing outside the perimeter — which is exactly what routing an agent role to an external model does.