AirOrchestra · a Torspan product
AirOrchestra — Where it runsIt runs on a computer you bought, in a room you lock.
The software is on it. The model that reads your crew's messages is on it. The database is on it, and so is every drawing you have ever loaded. We do not hold a copy of any of it. This page is what runs on that machine, the short list of what leaves it, whose account pays for the part that leaves, and the sentences we will not write about any of it.
09 The records are yours and they leave with you. Any day, whole, in files that open without us.
What is actually in the room
One computer. Not a rack, not a cabinet, not a room with a card reader on the door. A Mac on a desk in your office, on a wired connection, plugged into a small battery, in a room that locks — because from the day it goes in, it holds every record the company has.
Which of the three machines you get, what it costs and who buys it: Setting it up.
Four things live there, and all four are yours
- The database. Every hour with the sentence it came from, every message in the language it was written in, every photo with the man and the job beside it, every pre-task plan and every acknowledgement under it. One company's database, on one company's disk. There is no second company in it.
- The documents. Drawings, cut sheets, submittals, spec sections, dispatch sheets — as the files you uploaded, unchanged, plus the text pulled out of them so a man on a ladder can be answered off the right sheet.
- The model. An open-weight model under the Apache 2.0 licence, sized to the machine and held in memory so it answers at 6:30 in the morning instead of loading first. The licence and the exact version go on your receipt.
- The reading. The text comes out of your PDFs using the Mac's own built-in text recognition, on your machine, overnight, on hardware nobody is paying by the hour. The paper you already have gets read without one page of it leaving the building.
There is no account to create with us, no tenant, no workspace on somebody else's server, and no version of your data sitting beside another contractor's. There is no second contractor on that machine.
Almost the whole day never leaves the building
The work of an ordinary day — reading a message, understanding it, writing the records out of it, answering the man back — happens on the machine in your office. What goes out is the small pile of genuinely hard reading, and it goes out one item at a time.
| Stays on your machine | Goes out, and why |
|---|---|
| Every message from the crew, and every answer back to them | A drawing set or a plan sheet. Multi-page, cross-referenced, and the answer is where a thing is — which riser serves which unit on which floor. Often right is not good enough when often wrong sends five men to the wrong shaft. |
| Hours, with the sentence each entry was made from | A cut sheet where the answer becomes an order. CFM, static pressure, MCA and MOCP, dimensions, voltage. A transposed digit buys the wrong equipment with a twelve-week lead time on it. |
| Photos, filed to the job, with the person and his own words | A submittal or a spec section. Length. Two hundred pages does not fit in what the machine can hold at once, and cutting a legal document into pieces is how you miss the clause. |
| Pre-task plans, day plans, work reports, material requests, foreman questions | A photograph where the question is a judgement. "Is this hanger spacing to spec" is an opinion about compliance, not a thing in a frame. |
| Search over your own documents, and the answer with the sheet under it | Anything the model on your machine says it is not sure about. A machine that reports its own uncertainty is the cheapest correct place to draw this line. |
| The overnight pass — reading the paper, writing the day up, filling only what is genuinely known | Anything a man sends out on purpose. He types check this properly and it goes. The person standing on the job is allowed to spend the company's money on being certain. |
The rule, and there is no fifth line to it
Something goes out only if one of these is true, and the record of the turn says which one it was:
- The turn is reading a drawing, a cut sheet, a submittal or a spec section.
- The model on your machine says it is not confident enough.
- The question needs more of your record at once than the machine can hold.
- A person asked for it to be checked properly.
Everything else stays. A routine crew message does not leave the building — not once, not "just this one." Every turn carries which lane it went down and what triggered it, and the office can open that list any day and read it.
Invented shop, invented week. Real records belong to the companies that made them, and those don't go on a website. What the screen is, is the thing itself: every turn carries its lane and its reason, and the office reads them.
It goes out on your account, and you get the bill from somebody who is not us
This is the part most vendors would bury, so it is here, before you ask, in the same size type as everything else.
Most of the work happens on your machine. Some questions are genuinely harder than a machine that size — a busy drawing, a photograph that has to be read rather than filed. Those go to a commercial AI service, one page and one question at a time. Your company holds that account in its own name and pays that vendor directly for what it uses. We are not in the middle of it and we do not mark it up.
What is sent
- The page. Not the drawing set.
- The photograph. Not the album.
- The question. Not the conversation it came out of.
What is never sent
- The database.
- The message archive.
- Your people, your roles, your crew list.
- Your other jobs. Anything that is not needed to answer the one question that went out.
Three settings, and the middle one is what we recommend for your first month
| Setting | What happens | What it costs you |
|---|---|---|
| Automatic, logged | It goes out when the rule says so, and every call is written to a log you can open: what was sent, when, at whose request, and what came back. | Nothing. This is the normal setting once you have watched it for a month. |
| Ask me each time | Nothing goes out until somebody in your office says yes to that one item. | A pause in the middle of somebody's question. Worth it for the first month, because it is how the office learns what actually triggers it. |
| Off | Nothing goes out at all. Ever. | A real one, and here it is: the app tells your man it has not read the drawing, instead of reading it. That is a worse product and an honest one, and the switch exists. |
The one thing that never happens is a silent one. Nothing routes out without a line in that log. A product that decides on its own to send a page of your drawing to somebody else, with no entry you can find, has broken the promise even if the other company's terms are perfect.
Read the other company's terms yourself. Don't take ours for them.
The account is in your company's name, which means the contract for the reading that goes out is between your company and that vendor. You can read it without asking us, and you should.
The one we set up with you by default is Anthropic. Its commercial terms say the customer “retains all rights to its Inputs” and “owns its Outputs”, and that “Anthropic may not train models on Customer Content from Services.” Its published retention position for commercial products is that it “automatically delete[s] inputs and outputs on our backend within 30 days of receipt or generation,” with a zero-retention arrangement available by agreement.
Quoted from anthropic.com/legal/commercial-terms §B and privacy.claude.com, both read on 24 August 2026. We re-read them every quarter and the date on this line moves when we do. If one of them changed and this line is stale, write to us and it gets fixed the same day.
Why this is the strong half of the argument, not the weak one
- Your counterparty is that vendor, not us. You do not have to trust our summary of somebody else's promise. You can read the promise.
- The meter is yours. You see exactly what left and what it cost, on a bill from a company that is not us. No cloud product can offer you that, because in a cloud product the vendor pays for the reading and you see nothing.
- We cannot quietly widen it. A vendor who pays for the reading has a reason to send less. A vendor whose customer pays has a reason to send less and no way to hide it. The bill is the enforcement.
And when the month's budget is used up, it says so
You set a ceiling. The app warns the office on the way to it, itemised, with what spent it. When it is reached, the reading that goes out stops for the month — and the machine in your office keeps working for everybody all the way through it. Nobody's day stops because a drawing read is queued.
Invented crew, invented job. What it does not do is answer anyway. A product that fills the gap when it cannot read is the one you find out about eighteen months later.
Six things leave that machine, and here is all six
Every one of them is either something you switched on or something you can watch. The completeness of this list is the product feature. One thing found later that is not on it would be worth more damage than everything above it is worth in trust.
An update you pull
The machine asks our server whether there is a newer build, in the window you chose. What goes out is a version number. What does not go out is any record of yours — not a database, not a log, not a photo, not a message, ever, as a condition of installing anything.
You can pin a version. A machine that never updates again keeps working.
A subscription check
An identifier for the machine and a timestamp. Nothing else — no crew count taken from your records, no job names, no usage detail.
If our end cannot be reached, the machine keeps working. The check reports; it does not gate. A licence check that can stop a shop's dispatch on a Friday afternoon is not a licence check, it is a hostage.
A support session you open
Closed by default. There is no standing key, no permanent tunnel and no account of ours on the machine. Somebody in your office clicks a button, watches, and it closes itself.
Written on your side, with the time, the reason and how long it lasted: how that works.
A backup to a target you own
Encrypted before it leaves the machine, to a disk in your room and to an off-site destination you chose. Your account, your credentials, your keys.
We do not operate it, hold a key to it, or have a credential for it. We can see whether last night's run succeeded. Not what is in it.
An error report — off unless you turn it on
If you switch it on, what leaves is a stack trace and a build number, with record content stripped where it is produced rather than wiped afterwards.
Why it is off: an error report is the most common way a claim like this quietly stops being true, because the thing that reproduces the bug is the thing that contains the record. We would rather diagnose slowly.
A question on your own account
The dense drawing, the cut sheet, the photograph that has to be read. One page and one question at a time, on the account in your company's name, billed to you by that vendor, logged where you can read it.
The whole of it, with the settings: above.
The seventh line on that list is you
You email a closeout packet to a general contractor. You upload a report to somebody's portal. You print the file and hand it over. That carries more of your records off that machine in a normal week than everything above it put together, and it is not us — it is you using your own records, which is what they are for.
It is on the list anyway, because an honest boundary does not stop at the boundary that flatters us.
And the list of what we run at our end is one line long
There is no Torspan service holding, indexing, aggregating or making statistics out of anything of yours. No central photo store. No shared document index. No anonymised corpus. No "fleet dashboard" with your counts in it. Not because we haven't got around to building them — because building one turns your records are on your machine into your records are on your machine and also in our warehouse in aggregated form, which is the exact sentence that is already in three of the contracts a contractor has probably signed.
What our systems know about your machine: which version it is running, whether the subscription is current, and when a support session opened and closed. That is the line, and you can ask for yours.
Four things that are true because of where it runs
We do not train anything on your work
No model of ours learns from your hours, your photographs, your drawings or what your crew says. There is no aggregated dataset, no de-identified corpus and no statistical product built out of your jobs. There is no "to improve the Services" exception either, because we do not need one to run the business.
We are not the other side of a subpoena
Nobody can serve a document demand on us for your records, because we do not have them. Your own records are still discoverable — they always were, and anyone who tells you otherwise is giving you bad legal advice. What changes is that there is no outside company holding a copy, so discovery goes where it belongs: to you and your lawyer, who decide together what is responsive.
Leaving does not move your records
Cancel and the computer keeps working. The database is still yours, on your disk, and the export runs from your side. There is no sixty-day window to catch, no fee to pay and no retention clock counting down while you are not looking. What comes out, and what it opens in →
An attacker has to come for you specifically
A vendor holding tens of thousands of contractors' records is a target sized by all of them, and one flaw in it reaches every one at once. One machine inverts that arithmetic. It is not invulnerability and we never say it is — the disk is encrypted, the door is closed by default, and the honest half of the argument is further down this page.
One thing on that machine is not ours to switch off
This is the first thing a competent IT reviewer finds, so it is the last thing we want him to find by himself.
The computer is a Mac, and macOS talks to Apple the way every Mac in your office already does — clock, certificates, system updates. That is Apple's relationship with your company, not ours, and it is the same on the machine your bookkeeper uses. Your records are not part of it.
We cannot turn that off from inside the product and we do not pretend to. It is also why the sentence at the top of this section says six things leave and not nothing leaves. Nothing leaves is false at the operating system before a line of our software runs, and it is the one sentence that would end this argument the day somebody checked.
The disk is encrypted and the key is your company's
FileVault is switched on the day the machine goes in, and it is not optional. macOS “uses the AES-XTS data encryption algorithm to protect full volumes on internal and removable storage devices,” and on Apple silicon “all FileVault key handling occurs in the Secure Enclave; encryption keys are never directly exposed to the CPU.” Pull the drive out and put it in another computer and it reads as nothing.
The recovery key belongs to your company. We do not hold it, do not escrow it, and do not keep a copy just in case — holding it would turn the whole thing into a vendor-held key, which is the thing this architecture exists to avoid. Two people in your office hold it, from the morning it is switched on.
Quoted from Apple Platform Security — volume encryption with FileVault, read 24 August 2026. The consequence of both of your copies going missing is on Setting it up, and it is said before it happens rather than after.
Six sentences we will not write, and why
Every one of these would make this page stronger to skim and worthless to check. A rule with no reason under it gets re-argued by the next person who wants the sentence, so the reasons are printed.
| Not on this site | Why not |
|---|---|
| “Nothing ever leaves your machine.” | False at the operating system before our software runs, and false at the drawing reading. This is the one sentence whose discovery would end the relationship, and it would deserve to. |
| “Air-gapped.” | That means a machine on no network at all. Yours is on your network, and your men reach it from the field. The word has a meaning and this is not it. |
| “Subpoena-proof.” | Flatly wrong. Your own records are discoverable and always were. Saying otherwise is legal advice, and bad legal advice. |
| “100% private.” “Military-grade.” “Unhackable.” | None of them is measurable, and the first two are the vocabulary of companies who send a letter about it eighteen months later. |
| “Your data is safer with us.” | Safer is a comparison with no measurement under it. The shape is different — one machine, one company, no outside copy. Whether that is safer for you is your conclusion to draw, not our claim to make. |
| “The model on your machine is as good as the big ones.” | Not measured, on this work, on this hardware. When it is — on a named machine, on real turns, with a date on it — the number goes on the page as a measurement. Until then this page says where it runs and nothing at all about how fast. |
Nor is there a certification badge anywhere on this site. We do not hold one, and “designed to meet” is the same claim wearing a hedge. What a badge answers and what this company answers instead is on Your records.
What owning it costs you
Owning the machine is custody, and custody is work. Pretending it is nothing would be the same kind of lie as “nothing ever leaves.” Here is the whole of it, and here is the part of it that is ours.
It is a computer, and it needs what computers need
Power, a network, a backup that actually works, and somebody who notices when the disk is filling. We watch three of those four from a distance and tell you before they bite — the disk, the backup and whether the machine is up. The fourth is the wall socket.
We hold no copy, so a broken backup is not something we can rescue you from
There is no net on our side. That is the honest cost of the whole arrangement, and it is said on the day the machine goes in rather than discovered in month fourteen. It is also exactly why running the restore rehearsal is our obligation on a schedule, not a task on your list that nobody will remember. What a restore test has to prove →
When your office internet is down, the field cannot reach the office machine
This one is a genuine step back from software that lives in a data centre, and we say it out loud instead of letting you find it. Everybody in the building keeps working normally. The men in the field cannot reach the machine until the line is back, and what they sent is held on their phone and delivers when it is. Nothing is lost. Some things are late. Cellular failover on the office router is on the list of things we recommend, and it is your equipment.
It does not change what you have to keep, or for how long
It changes whether you can still get to it. The federal floors run five years on the injury log and thirty on exposure records; the window a subscription gives you after you leave is usually measured in weeks. That mismatch is what this fixes. Your own counsel still sets your schedule, and the software has no retention policy of its own, because that is a lawyer's decision and not a software default. The floors, with the citations →
What's live today
The rest of this site describes the product as it is meant to work. This is where that description and today's machine are the same thing, and where they are not. A block like this without a date on it is worth nothing.
Standing today
- The application runs on one company's database, on one machine, bound to that machine. There is no second company in it and no cross-company query to get wrong, because there is no second company.
- The text comes out of PDFs with the Mac's own built-in recognition, on the machine, at no charge, without the file leaving.
- The product does not answer about a document it has not read as though it had. It names the sheet and stops.
- There is no Torspan service holding, indexing or aggregating any of it. Nothing to switch off, because nothing was built.
Arriving with the machine
- The model on your own disk, and the split above. Today the answering runs on a machine of ours, against a commercial service. The version this page describes — the model on your disk, the two lanes, and the outside reading on your own account — arrives with the machine.
- The screen that shows what left the building. Every turn is going to carry its lane and its reason; the office-facing screen that lists them is being built with the rest of it.
- The boundary capture. Before the sentence “six things leave” ships against a running machine, that machine spends a full working day on an isolated network with a logger on it and every outbound connection gets compared to the six. If the capture disagrees with the list, the list is wrong and it gets fixed, not softened.
This block is not a schedule. There are no dates against the second list and there will not be, because a published plan gets read as a promise. If you want to know when one of them lands, write and ask, and you will get an honest guess from a person writing the code, labelled as a guess. The same block for the application itself, longer and older, is on What it won't do.
The machine is the only thing you buy before you start.
You buy it from Apple, on your account, in your company's name. We do not sell hardware, do not mark it up and do not take a referral fee — there is no line for a computer on any invoice we send, because we do not send one.
Six things leave that machine. We would rather print all six than be found out about one.
Questions about any line on this page go to admin@torspan.com and get a written answer from a person. There is no form on this site and no calendar to book.
AirOrchestra