KruschLaw is specifically engineered for high-stakes environments where attorney-client privilege, work-product doctrine, and data confidentiality must be preserved without compromise.
- Zero External Telemetry: KruschLaw contains no telemetry, analytics beacons, or remote logging services.
- 100% Local Inference: All embeddings and generative reasoning occur exclusively via your local Ollama instance or on-premise inference server.
- On-Premise Vector Database: All matter facts and law vectors are stored within your local PostgreSQL instance and never synchronized to cloud caches.
For law offices and corporate environments seeking maximal isolation:
- Localhost Network Binding: Ports in
docker-compose.ymlbind strictly to127.0.0.1by default (DATABASE_BIND_IP,BACKEND_BIND_IP,FRONTEND_BIND_IP), preventing unauthenticated LAN exposure. If remote access is required, deploy an authenticated TLS reverse proxy (e.g., Caddy or Nginx with client certs / OAuth). - Offline Web Application: The web dashboard is engineered with zero CDN dependencies. Web fonts rely exclusively on the client's local system typography stack, eliminating external HTTP requests upon page load.
- Ingest Directory Sandboxing: Parquet dataset ingestion strictly validates directory boundaries (
ALLOWED_INGEST_DIRS, defaulting to/app/dataand/app/data/ingest)./tmpis excluded by default to avoid symlink traversal and multi-tenant temp tampering. - Credential Rotation: Never use default passwords. Generate strong, unique credentials for
POSTGRES_PASSWORDin.env. - Firewall / Egress Filtering: For true air-gapping, enforce an operator egress firewall policy (
ufw default deny outgoing) or Docker internal network isolation. The application operates 100% offline. - Volume Encryption: Deploy persistent database volumes on an encrypted storage volume (LUKS on Linux, FileVault on macOS, or BitLocker on Windows).
- Matter Authorization (API Key): Set
API_KEYin.envto enforce token authentication (X-API-Key) across all case logging, review, and consultation endpoints, preventing unauthenticated matter exposure on shared office networks.
If you identify a security vulnerability, privilege escalation risk, or potential data leakage vector in KruschLaw:
- Please do NOT disclose the vulnerability in public GitHub issues or forums.
- Email the maintainer directly at security@krusch.io (or open a confidential GitHub Security Advisory) with detailed reproduction steps, proof of concept, and impact assessment.
- We will acknowledge receipt within 48 hours and work with you on a coordinated fix and patch release.