Protect model weights and inference hardware.
Trained weights stay on TPM-sealed hardware. Exfiltration requires physical compromise.
GPU and NUC inference endpoints enforce port policy at the kernel level.
Each research workspace runs on its own hardware root of trust.