05 / Field notes
Security, compliance and open-source AI infrastructure. Practical notes from the team building Xavani and the Security Cloud, written in the open.
Read the thinking. Explore the source. Put it to work.
Archive: our 27 August 2026 model comparison. Use the dated snapshot as a starting point for evaluation, not a live price list or a current Xavani default.
Xavani gives teams a local-first agent they can inspect and adapt. Here is why open code matters, and where configured cloud providers still cross the privacy boundary.
A staged route from monitoring to enforcement reduces avoidable mail disruption. Inventory senders, check alignment and review reports before changing your domain policy.
Use 90 days as a planning horizon, not a compliance guarantee. Map personal information, assign responsibility and build evidence with Gavaza and an accountable owner.
Make authorised scope, discovery and change review repeatable. Version the asset inventory and turn relevant changes into owned findings instead of another unattended report.
Test prompt injection, data boundaries and tool permissions in a controlled environment. Web auditing and LLM red-teaming are related disciplines, not interchangeable product claims.
Archive: a Kimi-focused evaluation note from August 2026. Check the exact model card and licence before treating open weights, context claims or hosted access as deployment approval.
Archive: what makes a local model useful in practice. For Qwen deployments, checkpoint licence, quantisation, memory and tool reliability matter more than a family-wide recommendation.
Archive: evaluating long-horizon work through Xavani. A dated model headline is not a guarantee of sustained reliability, consumer-hardware fit or current benchmark leadership.
Archive: a DeepSeek-focused note on speed and reliability. Pin the model build and test cost per completed workflow instead of treating an old Flash label as a current recommendation.
Archive: a practical view of multimodal-agent evaluation. Verify the selected MiniMax endpoint, supported inputs and licence rather than relying on historical architecture or speed claims.
An agent can plan, call tools and check outcomes. Useful business automation starts with one measurable workflow, explicit permissions and a human owner for consequential decisions.
Long-horizon reliability, useful memory, tool governance, evaluation and isolation. Five engineering questions for Xavani and its ecosystem, not a claim of solved agent safety.
Local inference can reduce third-party data exposure. Pair a suitable model runtime with Xavani, then verify hardware fit, network access, permissions and the cost of operating it.
Limited budgets, specialist capacity and infrastructure resilience shape security decisions. A practical South African approach combines maintainable tools, clear ownership and tested recovery.