Public marketing edge
thebriefcase.app — brochure, Suite directory, download links. May log standard web requests. No vault. No models. No family chat.
Network · privacy layers
Marketing can be public. Product organs are not. We layer so the Wi‑Fi guest next door never sees your forge, models, or vault — while you still reach them from a Mac on WireGuard.
The sandwich
thebriefcase.app — brochure, Suite directory, download links. May log standard web requests. No vault. No models. No family chat.
Named *.jailynmarvin.com (or your domain) behind nginx/Caddy + family auth. Only the doors you choose to publish. Everything else stays mesh-only.
Private overlay (example family plan 10.1.0.0/24). Peers: operator Macs, DGX Spark, NAS, VPS. Services bind loopback + WG IP — not 0.0.0.0 on house Wi‑Fi.
*.localhost doors on your Mac, The Briefcase App folder, Suite Get installs. On-machine truth. Organs talk over Docker/loopback; mesh is how other boxes join.
What stays private
LLM runtimes, RAG, ComfyUI, forge git objects — mesh or loopback. Not open on guest Wi‑Fi.
NAS vaults, model caches, backups — LAN/WG. Marketing site never sees them.
Family SSO, passkeys, Greet biometrics — your stack. Optional public sign-in only for doors you publish.
Binding law (family edge)Internal services bind: 127.0.0.1 + WireGuard IP (e.g. 10.1.0.5)
Never: 0.0.0.0 on house LAN for private organs
Reach paths:
1. On the box (loopback)
2. Over WireGuard mesh
3. Through a published, authenticated public door
Locks = authentication + network edge — not “security by hidden ports.”
You do not need everything
One Mac + The Briefcase.app. Local doors. No WG, no NAS, no DGX. Still private: product is on your machine.
Add WireGuard (GL.iNet or any WG router). Travel Mac joins mesh. Same doors, encrypted path home.
DGX Spark for models/forge, DXP6800-class NAS for vault, optional VPS edge for public gated doors.