A home AI trust boundary exists only when every read, transformation, model context, tool call, cache, and outbound path is technically mediated.
Running an agent on a home server keeps files off a cloud model by default, but local placement alone does not define trust. Parsers, plugins, vector indexes, logs, browser tools, and network connectors can copy sensitive content across boundaries. A defensible design classifies data, grants narrow capabilities, isolates untrusted processing, filters retrieval, controls egress, and records every approved crossing.
Classification and Mediation Define What Is Inside
Files receive owner, sensitivity, purpose, and allowed-consumer labels at ingestion. A trusted gateway resolves paths, verifies the requesting user and workload, checks policy, and returns only the minimum permitted content or derived feature. This distinction remains visible during later household testing.
Research on agent data pathways maps sensitive-data propagation through files, memory, tool outputs, and connectors in agent systems. This makes the boundary a graph of mediated flows rather than a circle drawn around one server.
Retrieval filters run before candidate text reaches the model, and caches include authorization scope. The model never decides its own permissions from prompt text; policy enforcement uses authenticated identity and current source access outside the model.
Capabilities and Isolation Limit the Reach of Compromised Components
The agent receives short-lived capabilities for a specific operation, path, mode, and purpose instead of broad filesystem credentials. Parsers and code tools run in sandboxes with constrained mounts, system calls, processes, memory, and network destinations.
A inherited file capabilities analysis argues that least privilege is easier when workers can use inherited capabilities but cannot open new sensitive resources. The principle maps directly to agents that should operate only on pre-authorized file descriptors or handles.
Separate identities for ingestion, retrieval, generation, and action reduce lateral movement. Encryption protects stored bytes, but once content is decrypted for inference, process isolation and output policy govern where it can travel. The intermediate result must remain inspectable before automation follows.
Egress Policy and Verification Govern Boundary Crossings
Outbound tools inspect destination, data classification, payload size, user intent, and required approval. Redaction or local summarization can reduce content before a permitted cloud call, while unknown destinations and prompt-derived URLs remain denied. That boundary should be measured separately under realistic operating conditions.
deterministic agent mediation explains that untrusted inputs, privileged access, and autonomous action together create an architectural exploit surface. Deterministic mediation breaks that combination by separating interpretation from authority. The practical consequence appears when several sources compete for limited context.
The failure boundary is a hidden copy path. Debug logs, crash dumps, embeddings, swap, thumbnails, backups, or browser uploads can bypass the visible agent interface. A boundary claim is valid only after enumerating and testing these paths, including behavior under prompt injection and component compromise.
Run a Sensitive-File Boundary Challenge
Create synthetic public, household, financial, health, and secret files with unique canaries. Test authorized reads, denied users, poisoned documents, malicious filenames, parser exploits, retrieval caches, tool arguments, browser uploads, logs, crash dumps, backups, and model-memory reuse.
Apply the capability boundary in capability trust boundary and record every canary crossing by process, user, purpose, destination, approval, and audit event. Remove one enforcement layer at a time to confirm the test can detect a real leak.
Pass only when allowed workflows receive the minimum data and every unauthorized route is denied or redacted outside the model. Any unmonitored egress, shared cache, or broad service credential makes the claimed trust boundary incomplete.
Tech & AI HUB
More to Read

What Factors Determine Whether Merkle-Tree Backups Detect Silent Change Efficiently?
Learn how chunk size, fan-out, trusted roots, cached hashes, change locality, metadata scope, and scrubbing determine Merkle backup verification cost.

What Components Enable Verifiable Backups of AI Indexes and Model State?
See how coordinated snapshots, content manifests, checksums, version locks, restore drills, and query tests prove that AI state can actually recover.

What Features Enable Complete Deletion From a Private Vector Database?
Learn how a private vector system traces one source through chunks, embeddings, indexes, caches, replicas, backups, and models to prove deletion.

