That’s true — Linggen can’t control the behavior of Claude or any other cloud LLM.
What it can control is the retrieval boundary: what gets selected locally and exposed to the model. If nothing is returned, nothing is sent.
If a strict zero-exfiltration setup is required, then a fully local model would indeed be the right option.