Vigil / Guides

Keeping Smart-Home Data on Your Own Hardware: Why No-Cloud Security Matters

Ask what a smart home knows about you and the answer is more intimate than most people expect. Not the individual events — a light turning on is trivial — but the pattern: when you wake, when the house empties, which rooms you use at night, when you're away for a week. Assembled over months, that pattern is a diary you never chose to write. The architecture question of the decade for smart homes is simple: where does that diary live?

What your smart home actually records

Even a modest setup generates a running behavioral record:

None of this is hypothetical telemetry. It's the working data any smart-home system needs to function. The only question is who else is in the room when it's processed.

What changes when it routes through a vendor cloud

The dominant smart-home architecture sends device state and sensor events to the manufacturer's servers, which run the logic and send commands back down. That design is convenient for vendors — and it has consequences for you:

Your data outlives your intentions

Once occupancy data sits on someone else's servers, its future is governed by their retention policy, their acquisitions, and their terms-of-service updates — all of which can change after you've bought the hardware. You can delete an app; you can't audit a datacenter.

You inherit their breach surface

A vendor cloud aggregates the schedules of every customer in one target. Your own Mac is a target only for someone who cares about you specifically; a platform database is a target for everyone. When a platform is breached, the customers absorb the harm.

Third parties can compel or request it

Data held by a company is subject to legal process served on that company, and to whatever sharing its policies permit. Data that exists only on hardware in your home enjoys the strongest practical and legal footing you can give it: to get it, someone has to deal with you.

Your house breaks when their servers do

Cloud-routed control means an automation as basic as "lights on when I walk in" makes a round trip through a datacenter. Vendor outage, discontinued product line, or your ISP having a bad night — and switches stop switching. A home shouldn't need permission from a server farm to run itself.

The subscription treadmill

When the logic lives on their servers, continued function becomes a service you rent, and features you bought can migrate behind new fees. Owning the compute means owning the behavior.

What "no vendor cloud" means concretely

The alternative is an architecture where the hub is hardware you own, on your own network:

The honest trade-offs

Keeping everything on your own hardware isn't free of costs, and it's worth naming them:

A one-question audit for any product on your shelf: if this company's servers vanished tonight, what would still work tomorrow? Sort your smart home by that answer and you'll know exactly where you stand.

How Vigil implements this

Vigil is built as the on-device answer: the hub is the Mac you already own. Device discovery and control run over your LAN; scenes and automations evaluate on the Mac; all sensing — acoustic sonar, optional camera pose, optional through-wall radio nodes — is processed on-device, and the raw sensing never leaves your Mac. The activity log is a file in your own Library folder, exportable and yours. The core runs with the internet completely off; the subscription is a software license, not a cloud dependency. If part of your goal is dropping cameras from the equation entirely, start with home security without cameras.

Your home's data, on your hardware

Vigil runs smart-home control and room sensing entirely on the Mac you already own — no vendor cloud, raw sensing never uploaded, and no sign-in or account required to run the app. Your subscription and download run through a website account, which holds your email and entitlement and nothing from inside your home.

Get Vigil — $25/mo