Governed private AI for critical telecom operations

AI that answers from your network — and can prove it.

Your teams ask any operational “How to?”. Locs answers from your approved knowledge and the systems actually installed and operational in your estate — evaluated before activation, governed at every step, measured honestly — all inside your environment. Flagship: Charging & BSS Assurance.

PERIMETER SEALED
GATE 01 — SIGNED IMPORTS ONLY
ANSWERSCONDITIONED ON YOUR ESTATE RAW DATA EGRESSZERO BY DESIGN DEPLOYMENTON-PREM / AIR-GAP BUILT BYmAIb TECH POWERED BYAOS-1
00
The flagship outcome

Any “How to?” — answered from your estate

A BSS engineer asks in plain language. Locs answers from the knowledge you approved and the systems actually installed and operational at your operator — vendor, version, environment, live status — with citations. Generic copilots answer from the internet’s network. Locs answers from yours.

  • The Operator Systems Registry: a governed, two-person-approved record of what is installed, which version, and whether it is operational right now.
  • Every answer is conditioned on that registry — a degraded system attaches an operational advisory to the answer.
  • A system you don’t run is refused outright, never improvised. Fail-closed, like everything in Locs.
  • Advisory only, source-cited, and receipted into the tamper-evident audit chain.
locs how-to — environment-aware answers · synthetic demonstration
01
What is Locs, exactly

Software you install. A portal your teams use.
Nothing leaves your network.

WHAT IT IS

A software appliance

Locs is enterprise software you run on your own servers — delivered as a hardened Docker package your ops team installs in under an hour. There is no cloud service behind it and no account with us: the AI model, your documents, and every answer live entirely on your infrastructure. It runs fully air-gapped if you need it to.

WHAT IT DOES

Answers from your own knowledge

Your administrators feed it the documents you already trust — SOPs, runbooks, ticket history, RCA reports. Your staff then ask it questions in plain language through a web portal, and it answers with citations to those documents, a confidence score, and a risk label. If it doesn't know, it says so instead of guessing.

WHAT YOU GET

A governed AI workspace

One appliance containing: three telecom copilots (BSS/Charging, NOC, Customer Care), an admin console for approving what the AI is allowed to know, an evidence centre your auditors can use, and a signed update mechanism to keep the AI current — plus installation, training, and a full document kit.

If you've used a public AI chatbot: Locs is that experience rebuilt for a regulated enterprise — it runs inside your network, answers only from documents you approved, shows its sources every time, and keeps tamper-evident records of everything it does.

locs.appliance.local — copilot workspace
The Locs copilot answering a billing question with cited sources, confidence and risk labels
The copilot your teams use — every answer cited, scored, and logged
locs.appliance.local — executive dashboard
The Locs executive dashboard showing governance metrics and the audit chain status
The executive dashboard — governance posture at a glance
02
The problem

Enterprises want AI.
They cannot expose
their data to get it.

Locs exists for organisations where AI failure, data leakage, and weak governance are not acceptable.

01

Uncontrolled external AI use

Prompts, tickets, configs, and customer records flow into public LLMs today — invisible to security, irreversible once sent. Locs gives your teams a sanctioned alternative that never exports raw data.

02

Local models go stale and hallucinate

A local LLM alone is weaker than frontier models and frozen at its training date. Locs enriches it with governed internal knowledge and refreshes it through verified, signed intelligence updates.

03

No governance, no deployment

Security boards refuse AI they cannot permission, approve, audit, or reverse. Locs is built around RBAC, two-key approvals, prompt controls, a kill switch, and full rollback — governance is the product.

04

Auditors ask questions AI can't answer

What entered the AI? Who approved it? What did it affect? Can it be reversed? Locs answers all of it from a hash-chained, tamper-evident evidence layer.

1–3%

of gross revenue leaks through BSS undetected, per industry surveys — rating and tariff errors alone are estimated at $5B a year industry-wide.

RAG survey 2021 · CFCA 2023
2.5×

Billing issues drive customer churn at 2.5 times the rate of any other factor — a cost analysts put above $1B a year at a major carrier.

Recon Analytics · 2026
£10.5M

One regulator's fine for a billing defect known internally for eight years — four times the sum actually overcharged. Persistence without evidence of remediation is what gets punished.

Ofcom · 2021
11 countries

lost mobile data service in 2018 when a single expired vendor software certificate failed — producing a compensation claim reported at up to £100M.

Public reporting · 2018

These are industry figures, not Locs results — Locs claims no outcome without customer-validated evidence. They are why governed, environment-aware AI for BSS operations exists as a category. And from 2 August 2026, the EU AI Act applies high-risk obligations to some operational AI: risk classification, documentation, audit trails, human oversight. Locs does not certify your compliance — it produces exactly that class of governance evidence by default.

03
Architecture

The governed knowledge lifecycle

Nothing becomes local AI knowledge unless it is classified, redacted, packaged, approved, versioned, and reversible. Watch the flow.

Ingest

SOPs & runbooksTickets / ITSM RCA reportsVendor manuals Sensitive data detectedCritical secrets blocked

Govern

ClassificationRedaction proof Knowledge packsTwo-key approval Security reviewRole permissions

Serve

Module-separated retrievalLocal LLM runtime Governed answer cardsConfidence & risk labels Fail-closed refusals

Improve

Knowledge gaps detectedSanitized outbound requests Outbound governance gateSigned offline bundles Versioned activation + rollback
0
Raw enterprise records sent to external LLMs
0
Security principles enforced in code
0
Actions receipted in the tamper-evident audit chain
0
Days from install to audit-ready evidence
04
Trust controls

Governance built into every layer

Local deployment protects the data boundary. Locs governance protects everything inside it.

T-01

Secret blocking

Credentials, keys, and tokens are detected deterministically and refused ingestion outright.

T-02

Classification & redaction

Subscriber identifiers, IPs, and hostnames are masked before anything is embedded or served.

T-03

Two-key approvals

No one activates their own knowledge. Security-flagged content requires a distinct reviewer.

T-04

Role-partitioned knowledge

Knowledge is separated per module and filtered by role at retrieval time — not in the prompt.

T-05

Kill switch

One governor action halts every AI path — answers, activations, exports, and bridge serving.

T-06

Tamper-evident audit chain

Every action is hash-chained and append-only. Tampering with history breaks the chain visibly.

T-07

Full rollback

Every update carries a rollback ID and impact map: modules, roles, and answers it touched.

T-08

Air-gap mode

One switch removes the outbound path entirely. Intelligence enters only as signed offline bundles.

05
Signed offline updates

External intelligence, imported like firmware

Locs improves your local AI the way critical infrastructure imports software: verified, signed, tested, approved, and reversible — never as a live external data bridge.

  • Knowledge gaps become sanitized, generic intelligence requests — identifiers stripped, with a term-level diff and redaction proof.
  • External frontier models are treated as intelligence processors, never as sources of truth.
  • Updates arrive as Ed25519-signed bundles with provenance, permissions, risk classification, and an embedded test suite.
  • A human approves every activation. Every activation carries a rollback ID.
locs verify — signed bundle import
06
Category

Why local LLMs alone are not enough

Public LLMsBasic local LLMsGeneric RAGLocs
Enterprise data stays localNOYESVARIESYES — by architecture
Frontier-grade intelligenceYESNONOYES — imported, verified, signed
Knowledge stays currentYESSTALEMANUALYES — governed update packs
Knows what runs in your estateNONONOYES — governed systems registry
Role-permissioned knowledgeNONOBASICYES — enforced at retrieval
Approvals & rollbackNONORAREYES — two-key, reversible
Audit-ready evidenceNONOLOGS ONLYYES — signed, tamper-evident
Fail-closed on high riskIMPROVISESHALLUCINATESUNSCOREDYES — refuses, opens governed gap
07
Flagship

Charging & BSS Assurance, powered by governed private AI

Locs does not merely keep AI private. Locs proves which private AI configuration is safe and effective for a defined telecom use case — and applies it to a structured charging & billing incident workflow. Advisory only; it never changes production systems.

ACHARGING & BSS

Incident-assurance workflow

Structured intake with redaction → classification → evidence-backed analysis (cited) → similar-incident and known-error retrieval → a safe diagnostic plan that separates read-only, approval-required and prohibited actions → vendor-case preparation → handover → governed post-incident knowledge capture. Every substantive claim cites approved sources.

BASSURANCE LAB

Evaluated before activation

A local model can still hallucinate, leak, follow injected instructions, or regress after an upgrade. Locs evaluates every model, embedding, retrieval config and prompt policy against a versioned, tamper-evident golden set — grounding, citation, refusal, and zero-tolerance leakage / prompt-injection / dangerous-output metrics — and refuses to activate anything that fails. Results are signed and independently verifiable. The model stays replaceable.

CHOW-TO ENGINE

Environment-aware answers

Any operational “How to?” is answered against the Operator Systems Registry — the governed, two-person-approved record of what is installed and operational at your operator. Matched systems and their live status ride with every answer; degraded systems attach advisories; systems outside your estate are refused, never improvised. Every ask is receipted and measured in the Value Centre.

Proof points: evaluated before activation · grounded in approved telecom knowledge · role-isolated · leakage- and injection-tested · citation- and refusal-measured · signed evidence · model replaceable · advisory only · air-gap capable. Locs does not claim perfect accuracy, zero hallucination, complete prompt-injection protection, production autonomy, universal telecom compatibility, certification, or customer ROI without customer evidence.

08
Platform

One platform, five product layers

01LOCS CORE

Local AI runtime

Local LLM deployment with a model-adapter layer — Llama, Mistral, Qwen, or your enterprise endpoint — plus governed, module-separated RAG. Recommended defaults, never lock-in.

02LOCS BRIDGE

External intelligence bridge

Manual, scheduled, and knowledge-gap update modes behind a full outbound governance gate: sanitization diff, redaction proof, risk scoring, security review, signed export.

03LOCS EVIDENCE

Trust evidence centre

Hash-chained audit log, approval records, redaction proofs, rollback history — exportable as signed evidence packs your CISO can verify offline.

04LOCS BUNDLES

Signed offline updates

Versioned knowledge artifacts with provenance, verification results, permissions, embedded test suites, and digital signatures. The update path that works fully air-gapped.

05LOCS TELECOM

Telecom pilot suite

BSS/Charging, NOC, and Customer Care copilots built from real operator workflows — charging logic, alarm triage, RCA drafting, complaint handling — with governed answer cards.

GOVERNED BY AOS-1 TRUST

Assurance-ready

Kill switch, human approval gates, tamper-evident hash-chained audit, and lineage IDs implemented to the AOS-1 Operating Assurance Standard — with signed execution receipts for continuous proof.

09
The 90-day pilot

Install to audit-ready evidence in 90 days

A fixed-scope program that proves governed private AI on your premises — and ends with an executive conversion pack, not a slide deck.

DAYS 01–15

Local deployment

Appliance install, local LLM configuration, roles and RBAC, classification rules, outbound governance posture, kill-switch drill.

DAYS 16–35

Knowledge ingestion

SOPs, manuals, ticket and RCA samples into BSS, NOC, and Care knowledge spaces — classified, redacted, permissioned, and approved through the workflow.

DAYS 36–55

Copilot activation

Governed answer cards live with pilot users. Source citations, confidence scoring, escalation behaviour, and refusal policy validated against real questions.

DAYS 56–75

Controlled intelligence updates

Knowledge gaps closed through the full loop: sanitized outbound requests, signed offline bundles, import verification, test suites, activation — and a live rollback demonstration.

DAYS 76–90

Evidence & conversion

Signed evidence pack verified in front of your security team, knowledge-quality metrics, and the full rollout roadmap with pricing.

10
Commercial model

An infrastructure program, not a subscription toy

Readiness assessment
£10k–£20k
  • Architecture & data-boundary review
  • AI-risk & knowledge-readiness review
  • Microsoft & infrastructure compatibility
  • Pilot recommendation & ROI baseline
Lighthouse pilot — Charging & BSS Assurance
From · scoped
  • Fixed price once scoped, 60–90 days
  • Locs live in your environment
  • One flagship use case, measured against a baseline
  • Signed evidence pack, verified offline
  • Credited against a qualifying platform agreement
Enterprise platform licence
Annual
  • Locs platform licence (per environment)
  • Telecom modules licensed per module
  • Deployment & integration scoped separately
  • Support SLAs included
Managed Assurance Programme
Annual
  • Knowledge refresh & gap closure
  • Signed offline bundle generation
  • Model evaluation & governance reviews
  • Evidence support for audits
11
FAQ

Questions security teams ask first

Privacy & architecture
Does any of our data ever reach an external LLM?

No raw enterprise data, ever. The only thing that can leave is a sanitized, generic intelligence request — after identifier stripping, a reviewable diff, a redaction proof, admin approval, security review where risk demands, and a digital signature. In air-gap mode even that path is disabled.

Which local models does Locs run?

Locs ships with recommended open-weight defaults for predictable pilots and abstracts the runtime behind a model-adapter layer — Llama, Mistral, and Qwen family models, or an enterprise-provided endpoint. You are never locked into one model family.

Can Locs run fully air-gapped?

Yes. The appliance requires no external connectivity. Intelligence updates arrive as signed offline bundles moved by your approved media process, verified and tested locally before activation.

Governance & security
What stops sensitive content entering the knowledge base?

Deterministic, security-reviewable detectors — not a model. Critical secrets (credentials, keys, tokens) block the document outright; subscriber identifiers, IPs, and hostnames are redacted before chunking; contextually sensitive content is routed to security review. Every detection is receipted.

What happens when the AI doesn't know the answer?

On high-risk topics Locs does not improvise: it states that approved knowledge is insufficient, shows what is missing, and opens a governed knowledge-gap request. Low-risk topics may receive cautious guidance clearly labelled as generic advisory.

Can the AI change our production systems?

No. Locs observes, retrieves, summarizes, recommends, and governs — humans execute all actions through your existing change processes. Assisted execution only, by design.

What does "governed by AOS-1 Trust" mean?

Locs implements the AOS-1 Operating Assurance Standard's runtime contract: a kill switch checked before every AI action, human approval gates on material changes, an append-only hash-chained audit log, lineage IDs on decisions, and signed execution receipts for continuous, verifiable proof.

Does Locs help with the EU AI Act?

The Act's high-risk obligations (applying from 2 August 2026) centre on risk classification, documentation, logging, transparency and human oversight. Locs produces that class of governance evidence by default — signed evidence packs, tamper-evident audit, fail-closed evaluation before activation, human-in-the-loop advisory design. Locs does not certify your compliance; your legal team makes that determination, with far better evidence in hand.

Deployment & pilot
How does Locs deploy?

Phase one is a portable hardened appliance (Docker Compose) installed inside your environment; Kubernetes and fully embedded high-security deployments follow. The local LLM, data, knowledge base, prompts, and inference always remain on your premises.

What do we have at the end of the 90-day pilot?

A working governed private AI deployment with your own knowledge, live copilots for BSS, NOC, and Care, closed knowledge gaps via signed updates, a demonstrated rollback, and a signed evidence pack — plus the executive conversion pack with rollout roadmap and pricing.

BUILT BY mAIb TECH

Locs is designed and engineered by mAIb Tech — built from firsthand telecom operations experience, not generic AI theory.

POWERED BY AOS-1

Runtime governance runs on the AOS-1 agentic operating system: kill switch, approval gates, tamper-evident hash-chained audit, and signed execution receipts.

Ready when you are

Keep your AI local, locked,
and defensible.

Book a technical briefing for your CTO, CISO, and AI governance board — or start scoping a 90-day telecom pilot.