Security & Privacy
Review local and hosted data paths, protect access, and make product-specific security changes.
Check the data path before submitting
Local runtime settings and hosted demo consent determine where processing happens. Check the selected service, permissions and retention information before sharing data.
Know where your data goes
Local runtime
With a local model and local processing configured, inference can run on your device. Hosted connectors, downloads, account services and application logging have separate data paths; review the settings for your deployment.
Hosted website demos
ThoxEmployee and EdgeLab send submitted text through hosted services after consent. Read the displayed provider notice before submitting and use synthetic, non-sensitive examples.
Stored demo information
The ThoxEmployee guest workspace stores instructions, task briefs, outputs and review activity with a 24-hour guest expiry. EdgeLab does not store prompt text or receipts in its application database; its usage limits use account and time-bucket records.
Privacy controls and limits
Clearing a guest workspace does not retract a request already sent to a provider or erase usage-limit records. The demo pages exclude marketing analytics, while necessary hosting, authentication and provider processing remain. The privacy policy explains these boundaries.
Protect accounts and device access
Use the required authentication
Follow the account and device access controls for the service you are using. Being on the same network does not authorize an application to access your runtime.
Separate identity from connectivity
MeshStack account access, registered device identity and native tunnel state answer different questions. An online device record or a browser identity alone does not establish a peer handshake.
Review permissions
Check the target, requested access and any tool permissions before approving an integration. EdgeLab logical profiles and model proposals do not grant execution authority.
Protect session and provider secrets
Keep passwords, private keys, session cookies and provider tokens out of prompts and support messages. Use the account or deployment controls to revoke access that is no longer required.
Make scoped network changes
Use the documented service settings
Read the ports, protocols and destinations required by the specific application and release. THOX products do not share one universal set of API ports.
Coordinate with the network owner
Limit any required rule to the intended application, device and network. Record what changed so it can be reviewed or reversed.
Keep system protections enabled
Do not disable the firewall, UAC or other security controls to force a connection. Start an application with elevated permissions only when its documented setup requires it.
Investigate network conflicts
If another VPN or network policy affects connectivity, record the symptoms and consult the administrator. Do not remove another VPN or expose device services to the public internet as an automatic fix.
Update the correct product
Match the release
Check the device model, application and operating system before selecting an update. Follow the release instructions for that product and verify the download source.
Prepare before installation
Read the release notes and back up the settings or work identified by the update guide. Keep power and the required connection stable during installation.
Use documented recovery
Offline updates, rollback and factory reset depend on the product. Follow an available recovery procedure for your release instead of applying commands from a different THOX device.
Confirm the result
Check the installed version and the functions you use after updating. If there is a problem, report the versions, failed step and sanitized error before attempting further recovery.