Silo Systems · July 2026

Silo Server.
Sovereign compute,
shipped as a product.

A stackable, offline-first private AI appliance that runs a firm's entire operational stack with zero cloud dependency. Ordered like a Mac. Scaled by clicking modules together. Engineered for the businesses that are legally barred from the cloud and structurally barred from building their own infrastructure.

Prepared by Omar Quddusi · Principal Architect · Silo Systems  ·  Document SS-BP-001 · Revision A · 4 plates · 16 registers · 12 decisions  ·  Formerly designated OBOX

Platform
AMD Strix Halo · x86-64
Fabric
SiloLink-E · 25GbE
Operating System
NixOS · immutable · A/B
Egress · Default
0 bytes · sealed
Assembly
California · BTO
Target Lead
10 business days
I · Thesis

The people who most need private AI
are the least equipped to build it.

Law firms, RIAs, medical practices, and accounting firms hold data they cannot lawfully or commercially place in a public cloud: case files, health records, portfolio allocations. The market forces them to choose between easy and private. Cloud AI is easy but not private. Enterprise on-prem hardware is private but not easy. Local-first tooling is a kit, not a product. Nobody sells private and turnkey as a single ordered object.

Silo Server closes that gap by turning private infrastructure into a consumer product. Each unit ships from the factory pre-configured with the full operational stack: local language models, retrieval over the firm's own documents, ingestion, access control, and the vertical template for the buyer's industry. The customer configures the machine online the way they would configure a Mac, and it arrives ready to run. Nothing phones home. The only network the machine knows is the one inside the building.

Capacity is physical. When the firm outgrows one unit, it orders another and clicks it onto the stack. The modules align magnetically, lock mechanically, and join a private fabric automatically. No rack, no integrator, no migration project. Scaling infrastructure becomes a purchasing decision instead of an engineering one.

This is not a cold start. Silo Systems has deployed this class of infrastructure by hand for consulting clients in regulated legal and financial services since 2019, under the internal designation Obox. The consulting practice proved the demand, funded the R&D, and supplies the design partners. Silo Server is the productization of work clients already pay for, aimed at the thousands of firms one consultant cannot reach.

Claim 01 · Physics
Private by physics, not policy
Data never transits third-party infrastructure. There is no vendor to breach, subpoena, or trust.
Claim 02 · Product
The Mac order experience
Configure online, receive a sealed appliance, plug in, work. Zero systems integration purchased or required.
Claim 03 · Scale
Capacity you can hold
Click a module onto the stack and the fabric absorbs it. Growth is a purchase order, not a project.
What this document resolves

The concept carried open engineering forks: compute platform, interconnect physics, memory pooling, OS, inference engine, data layer, model licensing, pricing, and manufacturing strategy. Every fork is closed in this revision with a reasoned decision, recorded in the Decision Register (§XI, D/01–D/12), each with the options weighed and the trigger that would reopen it.

II · Market & Buyer Mathematics

A compliance budget
looking for a product.

The buyer is a managing partner or practice principal at a 1–50 seat regulated firm. They already spend on compliance, IT, and per-seat software. They have watched competitors adopt AI and they have read their own bar opinions, HIPAA guidance, and client engagement letters. Their constraint is not budget. It is that every AI product offered to them requires surrendering custody of the one asset they are professionally obligated to protect.

Why now, specifically. Three curves crossed between 2024 and 2026. Open-weight models reached genuine professional utility at the 30–70B scale. Unified-memory edge silicon made 70B-class local inference possible in a shoebox instead of a rack. And compliance pressure on cloud AI hardened from theoretical to explicit, in bar ethics opinions, insurer questionnaires, and client outside-counsel guidelines. The window where a local appliance is both feasible and differentiated is open now.

TBL M-1US addressable sites · estimates, small-firm segment
SegmentUS sites (est.)Compliance driverBeachhead priority
Law firms≈ 450,000ABA Model Rule 1.6 · privilege · OCG clauses01 · primary wedge
Registered investment advisers≈ 15,000GLBA · SEC 17a-4 · Reg S-P02 · fast follower
CPA & accounting firms≈ 46,000IRC §7216 · GLBA safeguards03
Medical & dental practices≈ 230,000HIPAA · state privacy acts04 · post-v1
Addressable regulated sites≈ 740,000SAM: ≈ 180,000 sites at 5–50 seats with an active compliance driver
TBL M-2Buyer mathematics · 20-seat law firm · 3-year horizon
PathYear 1Years 2–33-yr totalCustody of client data
Copilot-class cloud AI · $30/seat/mo$7,200$14,400$21,600Transits vendor cloud · perpetual
Enterprise on-prem build · integrator + rack$60,000+$24,000+$84,000+Retained · staff burden retained too
Silo Server Studio + Care$8,487$5,976$14,463Never leaves the building

Silo path: Studio $5,499 hardware + Silo Care $249/mo. The appliance is cheaper than cloud per-seat pricing by year two, and it is the only path where the answer to a client audit question is a photograph of a box in a locked room.

TBL M-3Competitive field · why each incumbent solves half the problem
AlternativePrivate by physicsTurnkeyScales by moduleZero-access service model
Cloud AI APIs · OpenAI, Anthropic, AzureNoYesN/ANo
M365 Copilot · per-seatNoYesN/ANo
Dell · HPE · NVIDIA on-premYesNo · integrator requiredRack-scale onlyNo
AI workstations · Lambda-classYesNo · a computer, not a stackNoNo
DIY local · Ollama, Mac StudioYesNo · a hobbyNoNo
Silo ServerYesYesYesYes · §VI
The structural moat

Hyperscalers cannot follow. Their economics require centralizing customer data; "it never leaves your building" is a promise their business model cannot make. Hardware incumbents can build boxes but sell through integrators and have no vertical software, no compliance narrative, and no appetite for 20-seat law firms. The moat is the combination: appliance + vertical stack + ordering experience + zero-access service model, aimed at a buyer everyone else finds too small to integrate and too regulated to cloud.

III · Hardware Platform

One silicon decision
carries the whole line.

The concept document left the compute platform open between Apple Silicon, NVIDIA, and x86. This revision closes it: AMD Strix Halo (Ryzen AI Max 300 series) across every tier, differentiated by unified memory capacity alone.

The reasoning is recorded in full at D/01, but the shape of it: Apple does not sell M-series silicon to third parties, so an Apple-based appliance cannot legally exist at scale. NVIDIA Jetson Thor is a strong inference module but binds the entire software estate to CUDA on ARM at a materially higher cost per gigabyte of unified memory. Strix Halo delivers up to 128GB of unified LPDDR5X, an XDNA NPU plus a 40-CU RDNA GPU, full x86 compatibility, and, decisively, a supply chain already proven open to small integrators. One architecture means one NixOS image, one thermal design, one test jig, and one spares bin across the entire product line. For a build-to-order operation, fleet homogeneity is not a preference. It is the support model.

PLATE 01 · UNIT ELEVATIONS & INTERFACE MAPSS-BP-001 · REV A · MM · SCALE ≈ 1:2
Plate 01 · Silo Server unit elevations and interface map Three orthographic views of the 210 by 210 by 130 millimetre grid module, drawn to roughly 1:2. The front elevation shows the status and egress lamp, the engraved SILO SERVER wordmark and the lower-left intake vent array. The right-hand side elevation shows the SiloLink-X connector zone, a hexagonal vent field and four cam latches. The top plan view shows four corner alignment cones, the SiloLink-E blind-mate bus connector and the through-chassis airflow channels. Callouts A to F identify each interface; the notes beneath the drawing carry the same information as text. FRONT ELEVATION SILO SERVER 210 130 SIDE ELEVATION · RH SL-X 210 · DEPTH PLAN · TOP SL-E BUS · BLIND-MATE 210 A B C D E INTERFACE LEGEND A · STATUS & EGRESS LAMP · COPPER = SEALED / WHITE = CUSTOMER-ENABLED LINK B · INTAKE VENT ARRAY · ALIGNS ACROSS STACK GRID C · SILOLINK-X ZONE · SIDE FACES ×2 · PCIe G4 ×8 · RESERVED v1, ACTIVE v2 D · SILOLINK-E BUS · TOP + BOTTOM · 25GbE BLIND-MATE E · CAM LATCH ×2 PER MATING FACE · 25 KG SHEAR · TOOL-FREE F · REAR I/O · 2×10GbE · 2×USB-C (KEY-AUTHENTICATED) · C14 INLET · NOT SHOWN MATERIAL · 6063-T5 EXTRUSION + CNC FACE PLATES · TYPE II ANODIZE · BURNT COPPER · TAMPER-EVIDENT FASTENERS MASS ≈ 2.9 KG · VOLUME 5.7 L · GRID MODULE 210 × 210 × 130 · IDENTICAL ACROSS MINI / STUDIO / PRO PLATE 01 · UNIT ELEVATIONS SILO SERVER · GRID MODULE · ALL TIERS SS-BP-001 · REV A · 07.2026 DRAWN OQ · UNITS MM
NOTES · 1. All mating faces share the 210-grid; any face of any unit registers against any face of any other unit.  2. SL-E connectors present top and bottom on every tier; SL-X connector zone is populated on Studio and Pro, blanked on Mini.  3. Vent arrays are chassis-through channels; stacking aligns channels into continuous convection paths (see FIG X-1).  4. No fasteners are exposed on visible faces; service access via base plate.

The tier matrix

Three base units, one chassis, one image. Tiers are separated by unified memory and storage only, which is what actually gates local model capability. The concept document's TOPS figures are replaced with the platform's real envelope: a 50-TOPS XDNA NPU plus the RDNA GPU, with the GPU carrying LLM inference and the NPU carrying embedding and vision pipelines.

Model capability is stated in resident terms, not benchmark terms. A Pro holds a 70B model quantized to 4-bit, roughly 42GB, permanently resident with headroom for a concurrent 8B interactive lane, the vector index, and the application stack. That is the honest spec a buyer can hold us to.

Thermals, honestly

The concept called for fanless. Pure passive cooling caps sustained load near 25W, which cannot serve a 70B model, so the claim is revised to silent-first (D/02): a vapor chamber into a full-width fin stack, with two low-RPM assisted-convection fans that engage only under sustained inference. Mini runs passive in typical duty. The acoustic contract is printed on the spec sheet: under 24 dBA idle, under 32 dBA sustained at one meter. A machine sold to law offices is sold on silence, and we specify it like a dimension.

TBL H-1Base unit specification matrix · v1
SpecSilo Server MiniSilo Server StudioSilo Server Pro
Seats served1–3 users5–15 users15–50 users
SoCRyzen AI Max · 12-core classRyzen AI Max · 16-core classRyzen AI Max+ 395 · 16-core
Unified memory32GB LPDDR5X-800064GB LPDDR5X-8000128GB LPDDR5X-8000
Storage · ZFS encrypted1TB NVMe2TB NVMe4TB NVMe
Resident models≤14B Q4 + embed + vision32B-class Q4 + 8B lane70B Q4 resident + 8B lane
AcceleratorsXDNA NPU 50 TOPS (embed · OCR · vision) + RDNA GPU up to 40 CU (LLM inference)
Power · typ / peak65W / 120W90W / 160W110W / 240W
Acoustics @ 1m≤24 dBA · passive-biased≤28 dBA≤32 dBA sustained
I/O · security2×10GbE · 2×USB-C key-authenticated · TPM 2.0 · measured boot · internal 240W PSU · C14
Chassis210 × 210 × 130 mm grid module · 6063-T5 + CNC · burnt-copper Type II anodize · 2.9 kg
A single Silo Server module: a low, wide brushed burnt-copper anodized aluminium chassis with a square footprint, hexagonal side vent field and lit amber status lamp
FIG H-1 · SILO SERVER · SINGLE GRID MODULE · PRODUCTION-INTENT INDUSTRIAL DESIGNBURNT-COPPER TYPE II ANODIZE
Silo Server front elevation square to camera: horizontal intake vent slots at lower left, engraved wordmark at lower right, amber status lamp bar at upper right
FIG H-2 · FRONT ELEVATION · VENT SLATS + LAMP BARID STUDY
Mini, Studio and Pro units side by side: three identical burnt-copper chassis of the same size, distinguished only by an engraved tier name
FIG H-3 · MINI · STUDIO · PRO · TIER IDENTITY STUDYONE CHASSIS · MEMORY DIFFERENTIATES

Manufacturing posture · integrate, don't fabricate

Version one is an integration business, not a fabrication business (D/01, manufacturing clause). Mainboards are sourced as Strix Halo OEM modules from the same supply chain that already serves small system builders. The chassis is extruded and CNC-finished at a job shop in lots of 50–200, anodized to the burnt-copper specification. Assembly, flashing, burn-in, and QA happen in-house in California, which is both a cost decision and a brand asset: every unit ships with a serialized certificate of provenance, assembled and attested where the company lives. Contract manufacturing is milestone-gated at a sustained 500 units per year.

Regulatory engineering: internal power is a pre-certified PSU module, which confines compliance work to FCC Part 15 Class B emissions testing and ETL listing of the assembly. Budgeted at $30k and eight weeks inside Phase 2 of the roadmap (§X).

IV · SiloLink Interconnect

Scaling you can do
with your hands.

The signature interaction: lift a new module onto the stack, feel the magnets seat it, close two latches, and watch the fabric absorb the capacity. No cables between modules, no configuration, no integrator. This section specifies how that experience is engineered without a single dishonest claim underneath it.

Three physics problems had to be resolved. First, retention: magnets alone cannot safely carry a 2.9 kg cantilevered module against a shear pull, so neodymium cone pairs handle alignment and self-seating within ±1.5 mm, and dual tool-free cam latches carry the structural load at a rated 25 kg shear (D/04). Second, signal integrity: the concept's pogo-pin interconnect cannot carry modern serial lanes reliably at over 10 GT/s across a separable interface, so the electrical join is a blind-mate high-speed connector of the ExaMAX class, recessed behind the magnetic registration so it can never be force-mated. Third, the pooling claim itself, resolved below.

PLATE 02 · STACK TOPOLOGY & MATING INTERFACE · SECTION A–ASS-BP-001 · REV A
Plate 02 · Stack topology and mating interface, section A–A Left: a reference deployment of three stacked Pro modules plus a compute module. N1 carries the brain and ingress role running the user interface, PostgreSQL and Qdrant on the K3s control plane; N2 runs embedding and OCR batch pipelines; N3 is the deep runtime holding a 70B model resident. A compute module joins horizontally as a pooled worker. All vertical links are SiloLink-E at 25 gigabit Ethernet. Right: a 2:1 cross-section through two mating faces showing, from top to bottom, the dual cam latch, the neodymium alignment cone pairs and the recessed blind-mate high-speed connector. A strip along the bottom shows the fabric roadmap from SiloLink-E in version one to SiloLink-X in version two and a CXL memory research gate in version three. STACK TOPOLOGY · REFERENCE DEPLOYMENT · PRO ×3 + COMPUTE MODULE N3 · DEEP RUNTIME 70B Q4 RESIDENT DEDICATED INFERENCE · NO UI LOAD SL-E · 25GbE N2 · EMBED · OCR BATCH PIPELINE NPU-BOUND · INGESTION LANE SL-E · 25GbE N1 · BRAIN · INGRESS UI · POSTGRES · QDRANT K3S CONTROL PLANE · FIRM LAN UPLINK SL-E v1 SL-X v2 · PCIe G4×8 +C · COMPUTE MODULE POOLED WORKER · +64GB RPC WORKER v1 · TENSOR-PARALLEL v2 ROLES DECLARED IN silo.server.json · AUTO-ELECTION BY LOWEST SERIAL A NEW MODULE JOINS THE FABRIC IN < 90 SECONDS VERTICAL AND HORIZONTAL FACES CARRY IDENTICAL SL-E SEMANTICS IN v1 ORIENTATION IS ERGONOMICS + THERMALS, NOT PROTOCOL MATING INTERFACE · SECTION A–A · SCALE 2:1 MODULE A · FACE MODULE B · FACE NS 1 · DUAL CAM LATCH · 25 KG RATED SHEAR · TOOL-FREE · TAMPER-EVIDENT SEAL POINT 2 · NEODYMIUM CONE PAIRS ×4 · SELF-SEATING ±1.5 MM · POLARITY-KEYED, CANNOT MIS-MATE 3 · BLIND-MATE HS CONNECTOR · EXAMAX-CLASS · RECESSED · MATES ONLY AFTER REGISTRATION POGO-PIN INTERCONNECT REJECTED · SEPARABLE-INTERFACE SIGNAL INTEGRITY ABOVE 10 GT/s · SEE D/04 SILOLINK-E · v1 · SHIPPING 25GbE SWITCHED · ORCHESTRATION · K3S SILOLINK-X · v2 · SIDE FACES PCIe G4 ×8 NTB · TENSOR-PARALLEL POOLING CXL.mem · v3 · RESEARCH GATE SINGLE-NUMA POOLING · NOT MARKETED · D/07
NOTES · 1. Every joined face carries power-fault isolation; a failed module drops from the fabric without disturbing neighbors.  2. v1 power is per-unit via rear C14; the v2 vertical bus adds power sharing so a column draws through one inlet.  3. Fabric discovery is beacon-based over the SL-E link, no DHCP dependency, no firm-LAN exposure of inter-module traffic.
Close-up of the SiloLink mating face: machined guide channels, two recessed cam-latch pockets and a recessed rectangular blind-mate connector beside the hexagonal vent field
FIG X-2 · SILOLINK MATING FACE · GUIDE CHANNELS · LATCH RECESSES · CONTACT ARRAY (ID STUDY)BLIND-MATE · RECESSED · D/04

What the customer experiences

  • Seat it. The cones pull the module into registration; the connector blind-mates only once the faces are true.
  • Latch it. Two cams close by hand. The stack is now one rigid, thermally aligned object.
  • Watch it join. The fabric beacons, verifies the module's identity against its provenance certificate, and the console shows new capacity in under 90 seconds. Roles rebalance per the manifest: a second Pro becomes the dedicated deep-model runtime; a +S module becomes the replication target.

The pooling claim, made honest

The concept promised CXL.mem merged memory: a stack that behaves as one NUMA machine. Consumer-class silicon cannot do that today, and the claim would not survive one technical diligence call. The resolution (D/05–D/07): v1 delivers capacity pooling through workload placement over SiloLink-E, which is what buyers actually observe: more users, bigger models, faster ingestion. v2 activates SiloLink-X, a PCIe non-transparent bridge on the horizontal faces, enabling true tensor-parallel inference across adjacent modules, honoring the original design intent that horizontal means pooled compute, vertical means orchestration. CXL single-NUMA remains a v3 research gate, and is never marketed until it is real. The customer promise is stable across all three generations: click a module on, capacity goes up.

Two Silo Server modules joined side by side, warm light glowing from the vertical seam between them to indicate an active SiloLink-X fabric link
FIG X-3 · HORIZONTAL JOIN · SILOLINK-X ZONESEAM LAMP = FABRIC LIVE
Three Silo Server modules stacked into an orchestration column, a cam latch closed on each horizontal joint
FIG X-4 · THREE-TIER ORCHESTRATION COLUMNSL-E VERTICAL BUS · LATCHES CLOSED
Twelve Silo Server modules joined four wide and three high, their hexagonal vent fields aligned into continuous vertical convection channels
FIG X-1 · 4×3 STACK · 12 MODULES · VENT ARRAYS ALIGNED INTO CONTINUOUS CONVECTION CHANNELS384GB–1.5TB POOLED · ONE FABRIC
V · The Silo Engine

Software that treats the offline invariant
as a law of physics.

Every Silo Server runs the Silo Engine: an immutable, declaratively configured operating stack whose single governing rule is inherited from every product this company has shipped. Zero bytes egress by default. No telemetry, no accounts, no external APIs, no phone-home. The build system enforces it; the front lamp displays it.

The architecture extends the factory discipline already proven across the Silo app line: edit the manifest, re-emit everywhere. One file per machine, silo.server.json, declares the tier, the vertical template, the model pack, the role map, retention policy, and access control sources. From that one file the factory emits the NixOS configuration, the service topology, the compliance defaults, and the customer's provenance certificate. There is no hand-configured machine anywhere in the fleet, which is the only way a small team services a thousand appliances.

PLATE 03 · SILO ENGINE · LAYER STACK & SIGNED UPDATE PATHSS-BP-001 · REV A
Plate 03 · The Silo Engine layer stack and signed update path Seven stacked layers, from the private web console at the top down through local APIs and MCP servers, retrieval and the RAG indexer, the inference gateway, the llama.cpp engine, the immutable NixOS layer, and bare-metal Strix Halo hardware at the base. A bracket spanning every layer marks the offline invariant: zero bytes egress, sealed by default. To the right, the quarterly signed update path runs in five steps from inserting a FIDO2-attested SiloKey, through signature verification, staging to the inactive slot, a reboot behind a health gate and inference smoke test, to attestation and a ledger entry, with automatic rollback on failure. OFFLINE INVARIANT · 0 BYTES EGRESS · SEALED BY DEFAULT PRIVATE WEB CONSOLEREACT · VITE · LAN ONLY LOCAL APIS · WORKFLOWS · MCP SERVERSFASTAPI · LAN-SCOPED RETRIEVAL · RAG INDEXERQDRANT · POSTGRESQL · ACL AT QUERY TIME INFERENCE GATEWAYOPENAI-COMPAT ROUTER · SIGNED MODEL PACKS ENGINE · LLAMA.CPPVULKAN / ROCm · RPC MODE FOR MULTI-NODE IMMUTABLE OS · NIXOSsilo.server.json → configuration.nix · A/B SLOTS BARE METAL · STRIX HALO32–128GB UNIFIED · ZFS ENCRYPTED · TPM 2.0 SIGNED UPDATE PATH · QUARTERLY SILOKEY INSERT · FIDO2-ATTESTED MEDIA SIGNATURE VERIFY · DUAL OFFLINE KEYS STAGE TO SLOT B · CURRENT SLOT UNTOUCHED REBOOT · HEALTH GATE · INFERENCE SMOKE TEST ATTEST · LEDGER ENTRY · CERT UPDATED AUTO-ROLLBACK ON FAIL OPTIONAL CUSTOMER-ENABLED NETWORK CHANNEL EXISTS · OFF BY DEFAULT · ENABLING IT TURNS THE FRONT LAMP WHITE · THE MACHINE NEVER HIDES ITS STATE PLATE 03 · SILO ENGINE SS-BP-001 · REV A · 07.2026 · DRAWN OQ DATA PROTECTION · ZFS NATIVE ENCRYPTION · KEY = TPM 2.0 + ADMIN PASSPHRASE · HOURLY SNAPSHOTS · REPLICATION VIA ZFS SEND TO +S MODULE OR SECOND SILO SERVER OFFSITE (SILO MIRROR PATTERN) · NEVER A CLOUD BUCKET
NOTES · 1. MCP servers expose the firm's corpus to LAN-local tools only; the appliance is a first-class private context source for any MCP-capable client inside the building.  2. The inference gateway is OpenAI-schema compatible so vertical apps and third-party tools integrate without bespoke SDKs.  3. Engine choice is isolated behind the gateway; llama.cpp is the v1 engine (D/09) and is swappable without touching a single application.

Model packs are content, not firmware

Models ship as signed, versioned packs, decoupled from the OS image. The default packs are built exclusively from permissively licensed weights, Apache-2.0 and MIT class, which removes redistribution ambiguity from the product entirely (D/12). Meta-licensed models remain available as customer-selected packs with license passthrough. Quarterly pack refreshes ride the SiloKey update path, so a sealed machine still gets a better brain four times a year.

TBL E-1Default model pack · v1
LaneClassTier
FAST · interactive8B Q4 · permissive licenseAll
CORE · drafting · analysis32B-class Q4Studio · Pro
DEEP · reasoning · review70B-class Q4 · ≈42GB residentPro
EMBEDbge-large / nomic-classAll
VISION · OCR7B VLM assisting TesseractAll

Vertical templates

The tier is the hardware; the template is the firm. Selected at order time, a template overlays the engine with the industry's data model, retention policy, and prompt library:

  • LEGAL · matter-centric corpus, privilege tagging, conflict-wall ACLs, citation-first drafting library, WORM off.
  • RIA · client-account corpus, 17a-4 WORM retention on by default, books-and-records export.
  • MEDICAL · patient-centric corpus, minimum-necessary ACL defaults, audit-log verbosity raised.
  • ACCOUNTING · engagement-centric corpus, §7216 consent tracking, season-aware retention.

Ingestion is deliberately boring: drop files on the SMB share, SFTP, or an encrypted USB. Parse, OCR, chunk, embed, index. Documents keep their ACLs from the firm's directory (LDAP or AD), enforced as filters at query time, so an associate cannot retrieve across a conflict wall even by asking nicely.

VI · Security & Compliance Framework

Your records speak first.
The machine proves it.

Compliance marketing usually asserts conclusions. This product asserts mechanisms, and lets the buyer's counsel draw the conclusion, which is exactly how regulated buyers evaluate. Every claim below names the physical or cryptographic fact that produces it.

TBL S-1Threat model · who the machine defends against, and how
Adversary · scenarioCloud postureSilo Server mechanism
Vendor breach · your provider is compromisedYour data is in the blast radiusThere is no vendor holding data. Nothing to breach upstream.
Third-party legal process · subpoena served on a hostProvider may produce your data without youAll process must be served on the firm itself; counsel responds with full knowledge.
Physical theft · the box walks outN/AZFS native encryption, key sealed in TPM 2.0 + admin passphrase; measured boot refuses tampered images; chassis fasteners tamper-evident.
Insider exfiltrationProvider-side logging, opaqueUSB mass storage dead by default; only paired SiloKeys mount; every retrieval logged to an append-only dataset the admin cannot silently edit.
Supply-chain tamper · in transitOpaqueFactory-attested image hash on the provenance certificate; first boot re-measures and must match before services start.
Vendor snooping · usTerms-of-service trustZero-logical-access service model: Silo Systems holds no credentials to any deployed machine. Support runs on customer-exported, content-redacted diagnostic bundles.
TBL S-2Regulatory mapping · claim, stated by mechanism
FrameworkThe friction todaySilo Server posture
ABA Model Rule 1.6 · legalCloud AI use requires vendor diligence, disclosure analysis, sometimes client consentClient data never transits third-party infrastructure; the confidentiality analysis collapses to the firm's own premises and personnel, the posture bar opinions treat most favorably.
HIPAA · medicalEvery cloud AI vendor is a Business Associate; BAA chains sprawlNo cloud service exists in the data path, so no BAA chain exists for it. Where Silo performs on-site service, a BAA is offered; the default service model never touches PHI.
SEC 17a-4 · GLBA · financeWORM storage and audit trails via cloud archive vendorsRetention-locked ZFS snapshot policy with immutability holds; audit logs on an append-only dataset. Designed to 17a-4(f); independent assessment scheduled Phase 3 (§X). Sold as designed-to until certified, in writing.
Data sovereignty · allForeign-process exposure via hosting providersNo hosting provider exists. Jurisdiction over the data is jurisdiction over the building.
The zero-access service model · the claim competitors cannot copy

Support without custody: fleet homogeneity (one NixOS image) means most issues reproduce in the lab without ever seeing customer data. When a machine needs attention, the customer exports a diagnostic bundle to a SiloKey; the bundle contains system state and logs with document content structurally excluded, and its manifest lists every file it carries. A vendor that cannot access your data is a stronger compliance answer than a vendor that promises not to. This model is only possible because the fleet is immutable and manifest-driven; it is an architectural moat, not a policy.

VII · Product Line, Pricing & Unit Economics

Priced against the fear
it retires.

Pricing anchors to the buyer's alternative, not our BOM. A 20-seat firm's cloud AI bill runs $7,200 a year forever, with custody surrendered; an integrator-built private stack starts near $60,000. Silo Server prices between those poles, with hardware margin at appliance norms and recurring revenue attached to every unit (D/11).

TBL P-1SKU line · unit economics at 50-unit batch BOM
SKUWhat it isBOM est.PriceGross margin
Silo Server Mini1–3 seats · 32GB · ≤14B models$1,510$3,49957%
Silo Server Studio5–15 seats · 64GB · 32B-class$1,960$5,49964%
Silo Server Pro15–50 seats · 128GB · 70B resident$2,890$8,99968%
+C Compute moduleHeadless pooled worker · +64GB$1,430$2,99952%
+S Storage module8TB encrypted RAID-1 · replication target$1,260$2,49950%
+L Gateway moduleIsolated SFP+ interfaces · multi-tenant LAN$720$1,89962%

BOM basis: OEM Strix Halo mainboard, NVMe, extruded + CNC chassis and thermal assembly, pre-certified PSU module, SiloLink connector set, assembly and 48-hour burn-in labor, packaging with two SiloKeys. Margin improves up-tier because memory is the differentiator and memory is cheap relative to its price signal.

TBL P-2Recurring & services layer
OfferContentsPrice
Silo CareQuarterly signed update + model packs on SiloKey media · next-business-day support · hardware warranty maintained$249 / mo · site
Silo Care+Care, plus 4-hour response window · advance-replacement hardware · annual on-site inspection · extended warranty to 5 years$499 / mo · site
Silo DeployWhite-glove migration: corpus ingestion, directory integration, conflict-wall mapping, staff onboarding. The consulting practice, productized.$2,500 – $7,500 · one-time

The order experience

The configurator on the Silo Systems site is the product's front door, and it is deliberately shaped like buying a Mac:

  • 01 · Size it. Seats and document volume recommend a tier. Override freely.
  • 02 · Template it. Legal, RIA, Medical, Accounting. This writes the manifest.
  • 03 · Extend it. +C, +S, +L modules; extra SiloKeys; Care tier; Deploy.
  • 04 · Order it. 50% deposit funds procurement; balance on ship. Build-to-order, target 10 business days.

The deposit structure makes the business working-capital light: inventory is bought against orders, not forecasts.

What arrives in the crate

  • The unit, sealed, image flashed and attested at the factory.
  • Two paired SiloKeys, serialized to the chassis.
  • The Certificate of Provenance: serials, manifest hash, image hash, burn-in record, signed. The firm's first compliance artifact exists before the machine is even powered on. A ledger copy is retained by Silo Systems.
  • A one-page quick start. Plug into power and the firm switch, hold the front button, and the console appears on the LAN.
A Silo Server module seated in a charcoal presentation box with a debossed SILO SERVER lid, two paired SiloKeys and the provenance certificate in the tray beside it
FIG P-1 · AS DELIVERED · SEALED · FLASHED AND ATTESTED AT FACTORY · PACKAGING STUDYSILOKEYS + PROVENANCE CERT BENEATH TRAY
TBL P-3Reference orders · initial + annual recurring
ProfileConfigurationInitialRecurring / yr
Solo practitionerMini + Care$3,499$2,988
12-attorney firmStudio + Deploy + Care$8,999$2,988
Lighthouse · 30-attorney firmPro + S + Deploy(4.5k) + Care+$15,998$5,988
Growth eventAdd Pro to existing stack$8,999included
VIII · Operations · Order to DeliverySOP SS-OPS-01 · owner: principal architect · review: quarterly

A factory that fits
in a signature.

Every unit moves through one pipeline with four hard gates. Nothing ships around a gate. The pipeline is designed for a founder-led operation today and a contract manufacturer tomorrow, because every step is executed against the manifest and recorded to the ledger, the process itself is the training material for the first ops hire.

PLATE 04 · ORDER-TO-DELIVERY PIPELINE · GATES G1–G4SS-OPS-01 · REV A
Plate 04 · Order-to-delivery pipeline and gates G1 to G4 A nine-step pipeline running left to right: order with 50 percent deposit, manifest, procure, assemble, flash, burn-in, QA, ship, activate. Four quality gates hang below it. G1 after manifest requires schema and offline-invariant validation. G2 after flash requires the image hash attested to the device ledger. G3 after QA requires a soak pass of 97 percent or better under thermal and inference load. G4 at activation requires the customer's first boot to re-measure and match the factory hash. A ruler beneath marks the target lead time: order at day zero, parts pulled day two, assembled day five, soak begins day seven, QA passes day nine, ship day ten. ORDER50% DEPOSIT MANIFESTsilo.server.json PROCUREBOARD · SSD · CHASSIS ASSEMBLETORQUE-LOGGED FLASHNIX BUILD → IMAGE BURN-IN48H SOAK QACHECKLIST ×34 SHIPSEALED · INSURED ACTIVATEFIRST-BOOT ATTEST G1 · MANIFEST VALIDATES SCHEMA + OFFLINE INVARIANT G2 · IMAGE HASH ATTESTED RECORDED TO DEVICE LEDGER G3 · SOAK PASS ≥ 97% THERMAL + INFERENCE UNDER LOAD G4 · FIRST-BOOT CERT RE-MEASURE = FACTORY HASH D0 · ORDER D2 · PARTS PULLED D5 · ASSEMBLED D7 · SOAK BEGINS D9 · QA PASS D10 · SHIP TARGET LEAD · 10 BUSINESS DAYS · CEILING 15 · STOCKED-PART ASSUMPTION
NOTES · 1. G1 runs the same validator that governs every Silo product: schema plus invariants, including the hard-pinned zero-collection privacy posture.  2. G3 soak executes continuous inference against the shipped model pack at thermal steady state; a unit that throttles below spec fails, full stop.  3. G4 completes on the customer's premises: first boot re-measures the image and reports match against the provenance certificate before services start.
TBL O-1RACI · v1 operating roles
StepResponsibleAccountableConsultedInformed
Order intake · manifestConfigurator (automated)Principal ArchitectCustomerAssembly
ProcurementPrincipal ArchitectPrincipal ArchitectBoard ODM · chassis shopCustomer (lead time)
Assembly · flash · burn-inContract assembly techPrincipal ArchitectNoneNone
QA gate · G3Principal ArchitectPrincipal ArchitectNoneLedger
Ship · logistics3PL (milestone-gated)Principal ArchitectNoneCustomer
Activation · DeploySilo Deploy (services arm)Principal ArchitectFirm IT contactNone

Stated plainly: v1 concentrates accountability in the founder by design, with two contract roles carrying labor. The first full-time operations hire is milestone-gated at a sustained 15 units per month, and this SOP is the job description.

TBL O-2Exceptions & edge cases
ScenarioDisposition
Board DOA at flashSwap from spares bin (2 boards per 25 on order), RMA upstream; ledger notes serial substitution; lead time preserved.
Burn-in failure at G3Unit never ships. Tear-down analysis logged; component lot flagged; customer notified only if lead slips past D12.
Customer data migration exceeds Deploy scopeChange order under services rates; the appliance sale is never held hostage to the migration.
Field RMAAdvance replacement under Care+; drives are customer-retained on request (encrypted anyway); returned chassis wiped by key destruction, then re-imaged.
Lost SiloKeyRemaining paired key revokes the lost one; replacement key re-paired on premises. No remote revocation path exists, by design.
Metric · Quality
DOA < 2%
Field dead-on-arrival rate · measured at G4 activation reports
Metric · Speed
Lead ≤ 10 BD
Order to ship · 90th percentile · ceiling 15 BD
Metric · Reliability
Soak ≥ 97%
First-pass burn-in yield · lot-level trigger at two consecutive fails
IX · Go-to-Market & Financial Outlook

Sell where the trust
already exists.

The beachhead is California law firms of 5–50 attorneys, reached first through the standing asset most hardware startups lack: seven years of consulting clients in exactly this segment.

Phase one · design partners. Three lighthouse deployments drawn from the services book, sold at a 40% pilot discount, never free: regulated buyers do not value free, and paid pilots produce reference-grade contracts. Deliverable: three named case studies with before/after workflow numbers and a compliance memo the buyer's counsel signed off.

Four Silo Server modules stacked in a column on a shelf inside a clinical records cabinet, beside colour-tabbed patient file folders
FIG G-1 · DEPLOYMENT CONCEPT · CLINICAL RECORDS CABINETMEDICAL VERTICAL · PHI STAYS IN THE CABINET

Phase two · the configurator. Direct sales through the site, fed by the case studies, bar-association CLE talks, and the compliance-first content the consulting practice already produces. The founder's podcast and the legal-services network are distribution surfaces that already exist.

Phase three · channel. Legal-vertical MSPs and IT consultants, the people 20-attorney firms already trust, carry the product at 15–20% margin plus Deploy service revenue. The zero-access service model makes the channel comfortable: the box does not compete with their management contract.

TBL F-1Eight-quarter ramp · units & revenue · directional
QuarterUnitsHardware + servicesExit ARR (Care)
Q1 · pilots5$41k$12k
Q2 · GA12$112k$41k
Q322$204k$92k
Q435$318k$168k
Year 174$675k$168k
Q5–Q8260$2.4M$700k

Assumptions: blended initial order $8.6k rising to $9.7k with module attach; Care attach 80%, Care+ 25% of attach; Deploy attach 60% at $3.8k average; 3% quarterly churn on Care. Deposit-funded procurement holds inventory near zero. Gross margin blends to ≈61% hardware, ≈78% recurring.

TBL F-2Market sizing · two methods, one conclusion
MethodBasisResult
Bottoms-up · 3-year SOM0.5% of the 180k-site SAM · blended $12.4k initial + $3.4k/yr recurring≈ $11M initial · ≈ $3M ARR
Wedge capture · legal + RIA1% of ≈465k sites · $19k average site value at module attach≈ $88M hardware · ≈ $14M ARR
CeilingEvery business that would rather own its infrastructure than rent itThe Apple model, aimed at the office
X · Roadmap & Risk Register

Ninety days to a machine,
a year to a line.

TBL R-1Program roadmap · milestone gates G-A through G-F
WindowWorkstreamGate · exit criterion
Days 1–30NixOS image sealed (egress audit clean), manifest → configuration.nix emitter, ingestion daemons, FastAPI spine on Strix Halo dev boardG-A · image boots sealed; 0 packets egress under 72h capture
Days 31–60Inference gateway + llama.cpp tuning (Vulkan/ROCm), full RAG pipeline, 10,000-page retrieval benchmark, Qdrant + Postgres + ZFS layoutG-B · 70B Q4 ≥ 5 tok/s sustained on Pro board; P95 retrieval < 900ms over 10k pages
Days 61–90Chassis first articles + thermal validation, SiloLink-E bring-up between two boards, K3s auto-join, factory flash pipeline end-to-endG-C · two-module fabric joins < 90s; soak passes at spec acoustics
Months 4–6Pilot builds ×5, FCC/ETL testing, configurator live, Deploy runbooks, provenance ledgerG-D · 3 paying design partners activated at G4
Months 7–9GA. First 25 production units, Care logistics (SiloKey mail cycle), channel pilot with one legal MSPG-E · 25 units shipped · DOA < 2% · lead ≤ 10 BD held
Months 10–12SiloLink-X prototype (PCIe NTB tensor-parallel demo), 17a-4 assessment scoped, ops hire if ≥15 units/moG-F · 2-module tensor-parallel demo ≥ 1.6× single-node throughput
TBL R-2Risk register · named, owned, countered
RiskSeverityCounter
Silicon supply · Strix Halo allocation tightensHighDual-source across two ODMs; the manifest abstracts the board, so a board swap is a re-emit, not a redesign. Jetson Thor tracked as a priced fallback (D/01 revisit trigger).
SL-X signal integrity · PCIe over separable interface underdeliversMedv1 revenue does not depend on it; connector vendor eval boards before tooling; fallback is bonded dual-25GbE, which still doubles fabric bandwidth.
Founder bandwidth · solo founder, concurrent W-2HighNamed head-on: full-time trigger is funding or 10 paid orders, whichever lands first; SOPs written so the first ops hire absorbs assembly and logistics; consulting book converts to Deploy revenue instead of competing for hours.
Support burden · appliances in the fieldMedOne immutable image fleet-wide; zero-access diagnostics; A/B rollback means the worst field state is "previous known-good." Support cost modeled at $38/unit/yr inside Care COGS.
Compliance overreach · marketing writes a check legal can't cashMedMechanism-stated claims only (§VI); 17a-4 sold as designed-to until independently assessed; template review by outside regulatory counsel before GA.
Model licensing · redistribution terms shiftLowDefault packs are Apache/MIT weights only (D/12); restricted-license models ship as customer-selected packs with passthrough.
Price resistance · $9k sticker at small firmsLowBuyer math (TBL M-2) beats cloud by year two; leasing partner planned at GA so the lighthouse order lands under $650/mo, inside any firm's software budget.
Frontier-model envy · "the cloud model is smarter"MedPosition honestly: this is the best model your data is allowed to touch. Quarterly packs compound quality; optional customer-enabled hybrid egress exists but is never the default and never silent (the lamp).
XI · Decision Register

Twelve forks,
closed in writing.

The record of the engineering and business judgment underneath this document. Each entry states the options weighed, the resolution, and the condition that would reopen it. Decisions without reopening triggers are dogma; these are not.

D/01Compute platform & manufacturing posture

Options: Apple Silicon (best perf/watt, not licensable to OEMs); NVIDIA Jetson Thor (strong inference, CUDA/ARM lock-in, highest $/GB unified memory); AMD Strix Halo (128GB unified, x86, supply chain open to small integrators).

AMD Strix Halo across all tiers, differentiated by memory alone; integrate-don't-fabricate manufacturing, California assembly, CM gated at 500 units/yr.

Thor OEM module lands under $1,800 with 128GB-class memory, or Strix allocation fails two consecutive builds.

D/02Fanless claim → silent-first

Pure passive caps sustained load near 25W and cannot serve a 70B model. The honest product is a specified acoustic contract, not a cooling ideology.

Vapor chamber + low-RPM assisted convection; ≤24 dBA idle, ≤32 dBA sustained at 1m; Mini passive-biased in typical duty.

A ≤40W SoC serves the Studio workload; Mini goes fully passive.

D/03Form factor · the 210 grid

One module size across the entire line: 210 × 210 × 130 mm, 5.7L, 2.9 kg. Any face registers against any face; vent channels align across the stack. Half-modules rejected for v1: two SKUs of sheet metal is one too many.

Single grid module, all tiers and expansion modules identical externally.

A rack-adapter SKU is demanded by >10% of orders (a 19-inch tray holding two modules is the pre-designed answer).

D/04Mechanical & electrical join

Magnets cannot carry structural load; pogo pins cannot carry >10 GT/s across a separable interface reliably.

Neodymium cones align (±1.5mm, polarity-keyed); dual cam latches retain (25 kg shear); blind-mate ExaMAX-class connector carries signal, recessed so it mates only after registration.

Connector vendor qualification fails at PCIe G4 rates; fall back to bonded dual-25GbE on the X faces.

D/05v1 fabric · SiloLink-E

One protocol on every face: 25GbE switched, beacon discovery, K3s orchestration, roles from the manifest, auto-election by lowest serial. Orientation is ergonomics and thermals, not protocol, which makes the v1 product impossible to mis-assemble.

Uniform Ethernet-class fabric; join under 90 seconds; zero customer configuration.

Never; this remains the control plane even after SL-X ships.

D/06v2 fabric · SiloLink-X

Honors the founding intent: horizontal means pooled compute. PCIe Gen4 ×8 non-transparent bridging on the side faces enables tensor-parallel inference across adjacent modules.

SL-X specified into the v1 chassis (zone reserved, Studio/Pro populated) so v2 is a firmware-and-module story, not a new chassis.

G-F gate: ships only if the 2-module demo exceeds 1.6× single-node throughput.

D/07CXL.mem single-NUMA pooling

The concept's merged-memory claim is not achievable on consumer-class silicon today and would not survive technical diligence.

Deferred to a v3 research gate, contingent on CXL-capable edge silicon. Never marketed until real. The customer promise ("click a module on, capacity goes up") is already true in v1 by workload placement.

CXL 3.x memory pooling appears in a ≤120W SoC roadmap from AMD or NVIDIA.

D/08Operating system & update path

Options: NixOS vs custom Yocto. Yocto means maintaining a BSP, a team's worth of work. NixOS gives declarative single-source config (the manifest philosophy the whole company runs on), reproducible builds, and atomic A/B rollback.

NixOS immutable; silo.server.json → configuration.nix; quarterly signed updates on FIDO2-attested SiloKey media; optional customer-enabled network channel that turns the lamp white.

Fleet exceeds 2,000 units and OTA economics dominate; the signed-channel design already anticipates it.

D/09Inference engine

vLLM's ROCm APU support is not mature enough to bet the fleet on; MLX is Apple-only and Apple is out (D/01).

llama.cpp (Vulkan/ROCm) behind an OpenAI-compatible gateway; RPC mode reserved for multi-node. The gateway isolates the engine so it is swappable without touching applications.

vLLM (or successor) demonstrates stable Strix Halo serving with ≥30% throughput gain on the 32B lane.

D/10Data layer

pgvector-only rejected: at multi-million-chunk corpora with per-document ACL filtering, a dedicated vector engine wins on filtered HNSW performance and operational isolation.

Qdrant (vectors) + PostgreSQL (application) + ZFS native encryption, hourly snapshots, replication by ZFS send to a +S module or an offsite Silo Server (Silo Mirror). Keys sealed in TPM 2.0 + admin passphrase.

Corpus profile at real customers stays under 500k chunks median for a year; revisit consolidation to shrink the surface.

D/11Pricing architecture

Anchored to the buyer's alternatives (cloud per-seat forever vs $60k integrator build), not to BOM. Hardware carries appliance margin; the relationship carries recurring.

$3,499 / $5,499 / $8,999 base tiers at 57–68% gross margin; modules $1,899–$2,999; Care $249 and Care+ $499 monthly per site; Deploy $2,500–7,500. 50% deposit at order.

Pilot cohort closes at >80% without negotiation; raise Pro to $9,999 at GA.

D/12Model licensing posture

Bundling Meta-licensed weights in a commercial appliance adds redistribution terms and attribution mechanics a regulated buyer's counsel will ask about.

Default packs are Apache-2.0/MIT weights exclusively (Qwen and Mistral class). Restricted-license models offered as customer-selected packs with license passthrough. The spec sheet's capability claims are written against the permissive default.

A restricted-license model becomes decisively superior for a vertical workload; ship it as a named optional pack, never the default.