Host-only product surface
Only The Briefcase.app by default. No pre-stamped junk. Suite Installer Get is the sole path that adds Console/Native to the product folder.
Security · first pillar
Local-first. Mesh-bound. Host-honest. We design for a Family Office that owns its hardware and network — not a rented control plane as the only home for family data.
Model
Reduce what is installed. Reduce what is listening. Reduce what is public. Make every expansion an operator decision — Suite Get, peer keys, published doors — never a silent warehouse or a surprise cloud.
Controls
Only The Briefcase.app by default. No pre-stamped junk. Suite Installer Get is the sole path that adds Console/Native to the product folder.
Private organs listen on 127.0.0.1 + WireGuard IP. Not open on guest Wi‑Fi. Locks = authentication + network edge — not “security by obscurity.”
WireGuard mesh (GL.iNet-friendly). Encrypted path to home compute/NAS. Optional for desk-only operators.
Family SSO, passkeys, optional Greet Native biometrics. Public sign-in only for doors you publish on a gated edge.
.pkg / .dmg packages, product folder stamp, prune on reinstall. Checksums when you distribute builds.
thebriefcase.app is brochure + Suite sites + guides. It does not host your vault. See privacy.
Threat orientation
0.0.0.0 binds pretending to be “just LAN”What we do not claim: invulnerability, anonymity networks, or that misconfiguration is impossible. Operators still own firewall discipline. We make the secure path the default and the documented path.
Operator checklist