Authentication and MFA
Access management with time-based second factor and session administration from the node.
Technology and security
This page is written for sysadmins, engineers, security architects, and developers. No unnecessary adjectives: engines, interfaces, controls, and known limits.
Public diagram
Public view. We don't publish internal paths, credentials, sensitive network details, or unmitigated vulnerabilities.
Engines and foundation
| Component | What it does | Stated limit |
|---|---|---|
| Unified panel | Dashboard, chat, models, downloads, APIs, inference, security, users, network, firewall, services, and power. | We don't claim full enterprise observability. |
| Hardware telemetry | GPU and VRAM, power, CPU/RAM, temperature, disks, and service status. | Sensors depend on the physical host. |
| Local inference | GGUF models with OpenAI-format-compatible streaming; context, threads, fast attention, KV cache, and tensor split. | Not every GGUF runs on every binary or hardware. |
| Catalog and proxy | Catalog, health, load/unload, chat and admin endpoints, published profiles. | Depends on weights downloaded beforehand. |
| Lanes | base, gpu0, gpu1, dual, and cpu to distribute workloads. | Concurrency limited by VRAM. |
| Text and vision | Vision component with multimodal projection and images via URL or data. | Requires mmproj compatible with the model. |
| Chat | SSE streaming, client-side history, transcription, visual attachments, and metrics. | History is managed on the client side. |
| Profiles and VRAM | Draft → test → publish cycle and memory estimation before building stacks. | The estimate is not an exact guarantee. |
| Frontier mode | Suspends the usual stack, loads a large model, and restores after idle time without cutting active inference. | Switching can take several minutes. |
| Voice a texto | Local transcription with unload on idle. | Quality depends on input audio and language. |
| OCR / documents | PDF, Office, images, and CSV to text, ES/EN. | Depends on original scan quality. |
| Inference API | HTTPS endpoints with scope-limited keys. | Compatible only on supported endpoints and structures. |
| Network / HTTPS | TLS termination and controlled external exposure. | Network policy is defined by the organization. |
| Optional modules | GameDev-MCP / Unreal, SIP telephony, sync between nodes, and explicit external providers. | Activated per project and agreement. |
Security
We don't say a system is "100% secure" or "impossible to hack." We describe which controls exist and who is responsible for each layer.
Access management with time-based second factor and session administration from the node.
Per-integration keys with limited scope, revocable, with usage logging.
Security and inference logs to reconstruct access, changes, and queries.
Encryption in transit and port and rule management from the panel itself.
Human and application identities with differentiated roles and least privilege.
Agreed backups and phased installation on a clean server, with verification.
Shared responsibility. Xeretron provides technical controls and supported operations; the organization maintains access policy, network management, and compliance with its regulatory framework. We don't claim automatic regulatory compliance.
Indicative requirements
30-minute demo, in person or remote, with a technical lead on your side if you want.