# Security ยท Good AI Labs > Model connections, tool permissions and local deployment. URL: https://www.goodailabs.com/security/ Colony and re1 can run on the operator's infrastructure. The model connections and tools configured for a deployment determine where data is sent. An air-gapped setup needs local models and all required tool dependencies installed inside the network. ## Models and tools Colony does not provide a hosted model. You can configure a local inference server or an external endpoint. Its daemon makes no telemetry calls. Agents access external services through the connections and tools they are granted. Installed Colony builds also check for new releases. Automatic updates can be disabled for installations that use an internal update process. Tool permissions, policy checks and execution records are part of the runtime. A deployment review should cover the configured models and tools as well as the daemon itself. See [Budgeting a local decision service](/blog/security-review-is-the-market/) for the request path. ## This website This is a static site with locally served fonts, images and JavaScript. It uses scripts for graphics and navigation. It sets no cookies and runs no analytics or third-party embeds. The [privacy notice](/privacy/) covers hosting logs and email correspondence. ## Security contact Send security questions or vulnerability reports to [research@goodailabs.com](mailto:research@goodailabs.com?subject=security). We reply within two working days. Contact: research@goodailabs.com