Skip to main content
Locus

Enterprise

Locus for organizations

The same local-first search engine, wrapped in org identity, seats, and (eventually) central billing — built for a team that already shares a network drive everyone can already read, and wants that drive to be instantly searchable by AI without building a pooled index anyone with a compromised account could scrape in bulk.

What is live today.

The org/roles layer below is live in production today. Billing, per-subfolder access control, and SSO/SCIM are not — see "Not built yet" below before you assume anything. This page exists to collect real interest in parallel with the build, not to promise a finished Enterprise product.

How it works

  • Your IT already mounts the shared drive for other tools — a drive letter, a /Volumes mount, an fstab/autofs entry. Locus just points at that same local path, the same way it indexes any other folder. It does not implement its own SMB/NFS credential storage or mounting.
  • Each employee's own Locus instance reads the share under their own OS session, so nobody sees anything through Locus they couldn't already open directly on the network.
  • The org layer (this page's subject) only adds identity, seats, and roles on top — never a shared search index across employees.

Live today

Org identity, invites, and roles

Owner/admin/member roles, email invites with expiry, and an audit log — built and smoke-tested against production on 2026-09-21. Live at /dashboard/org for any signed-in account today.

Per-user local indexing, not a pooled index

Each employee runs their own local Locus instance under their own OS session and credentials — mechanically identical to pointing locus index at any other folder. No centrally-built shared index exists or is planned; an org admin has no access to an employee's personal files.

Admin key revocation

An org admin can revoke a departing or compromised member's API keys without removing them from the org, separately from full member removal.

Seats are free to create right now

Billing isn't wired yet, so there's no seat cost today — stated in-product, not a promotional rate.

Already have teammates using Locus individually? Create an organization for free at /dashboard/org today — no waitlist required for the roles layer itself.

Not built yet

Stated plainly, not glossed over — this is what "Enterprise" does not mean today:

Billing and seat pricing

No checkout is connected for Enterprise. A per-seat price will be quoted directly once we've run a real worst-case cost check at organization scale — we're not guessing a number here.

Per-subfolder access control

The current design assumes flat, equal read access within a connected shared folder (e.g. an "Everyone: Read" network drive). It does not mirror differentiated per-subfolder permissions — if part of your drive is restricted to some employees, that needs real ACL-mirroring work we haven't built.

SSO / SCIM

Sign-in is email and password, or Google or GitHub, through Supabase. No SAML/OIDC SSO and no SCIM provisioning yet.

Managed fleet rollout

There's no push-config or central update mechanism for employee installs. For now this is "IT follows a documented per-employee setup guide," not a centrally managed fleet.

Compliance paperwork

A DPA draft exists (not yet lawyer-reviewed or signed) and we use SOC 2's Trust Service Criteria as a checklist, but no audit has been performed and no SOC 2 report exists — that's a paid audit we haven't run. If a signed DPA or an actual SOC 2 report is a requirement for your procurement process, say so — it tells us how to prioritize it.

A security note, plainly stated

Under this design, a stolen or compromised employee laptop can read (and, if configured to use a hosted embedder, transmit chunk text from) anything on the mapped network share that employee could already open — the same access that laptop already had, Locus just makes it AI-searchable on top of it. Until this is reviewed further, we recommend the local embedder (LOCUS_EMBEDDER=local) for Enterprise deployments specifically, so indexing never sends chunk text over the network. Search results still go to whichever AI assistant each employee uses. The free local mode is optimized for English; managed mode uses a multilingual model. We have not yet measured search quality in other languages.

If you're evaluating our security posture

If your process is "can someone explain how this actually protects our data" rather than "send us your SOC 2 report," /security answers that today, honestly — real access controls, a written incident-response runbook (not yet drilled), what doesn't exist yet stated plainly, no report required to understand any of it. If your process specifically requires a formal SOC 2 report, ISO 27001 certification, or a signed security questionnaire referencing an audit — say so in the form below. We don't have one yet, and that's worth knowing up front rather than discovering partway through a sales conversation; real demand for one is exactly what would move it onto our roadmap, not a decision made in the abstract.

Tell us about your use case

Team size, what your IT already manages, and what you'd need before rolling this out — real signal helps us prioritize correctly instead of guessing.

Optional. We use your message only to reply. Privacy · Terms · Sub-processors

Opens your own email client, addressed to yonilev2003@gmail.com, pre-filled from what you typed above. Nothing is stored here — we only see it once you actually send it.

Nothing on this page is a binding offer or a signed agreement. Pricing, compliance posture, and access-control scope are all subject to change before any real contract.