Keep the model close to the evidence when the evidence must stay local.
Run BrainStorm security investigations with a local model so raw log analysis can remain within the customer environment.
BrainStorm can use local model runtimes as well as hosted providers. For security investigations, that creates a simple deployment choice: keep the model, gateway and Logs MCP server inside the customer boundary when raw logs should not leave it.
Local does not mean isolated
A local model can still call explicitly configured external backends. If the investigation queries Falcon, those Falcon API/MCP calls go to CrowdStrike. The important point is that the raw log corpus does not have to be uploaded to a hosted LLM merely to be searched.
Same governance either way
The model location does not change Steward policy, agent restrictions, backend configuration or Windows resource permissions. Hosted and local models can therefore share the same execution boundary while different data-residency rules apply to different investigations.
