🌲
myalaska.me White Paper WP-02
Volume I: AlaskaVault
HYBRID VECTOR + FTS5 Volume I: AlaskaVault • 16 min read

Air-Gapped Hybrid Neural Search: Running Vector & FTS5 Pipelines Without Cloud LLMs

Decoupling Semantic Retrieval from Centralized AI APIs: On-Device Vector Embeddings, BM25 Lexical Ranking, and Zero-Packet Egress.

Author AlaskaVault Machine Intelligence Group
Published October 2026
Target Audience Enterprise Architects
Architecture 100% Zero-Cloud

Air-Gapped Hybrid Neural Search: Running Vector & FTS5 Pipelines Without Cloud LLMs

White Paper ID: WP-02

Author: AlaskaVault Machine Intelligence Group

Classification: Public Enterprise Specification

Architecture: Pure-Local Hybrid Search (FTS5 BM25 + Dense Vector Embeddings)


Executive Summary

The rapid enterprise adoption of Large Language Models (LLMs) and Retrieval-Augmented Generation (RAG) has introduced a catastrophic security vulnerability: corporate intellectual property egress. Modern cloud-based AI search engines require sending proprietary source code, patient health records, internal memos, and legal contracts to third-party cloud APIs (such as OpenAI, Microsoft Azure AI, or Google Cloud Vertex). Once transmitted, this data is exposed to API logging, employee snooping, model provider retraining, and foreign subpoena requests.

AlaskaVault eliminates this trade-off by introducing Air-Gapped Hybrid Neural Search. By fusing quantized local embedding models with high-performance SQLite FTS5 lexical indexing (BM25), AlaskaVault executes millisecond-latency semantic and exact-match search entirely inside a local, air-gapped enclave. Not a single byte or packet leaves the host machine. This paper details the mathematical foundation, quantization mechanics, and Reciprocal Rank Fusion (RRF) pipeline that powers AlaskaVault's offline search engine.


1. The Cloud AI Security Trap

1.1 The RAG Data Egress Surface

A typical enterprise cloud RAG architecture introduces multiple attack vectors:

  • Embedding Egress: Documents are chunked and transmitted via HTTPS to cloud embedding endpoints (text-embedding-3-small, etc.).
  • Cloud Vector Stores: Dense vector embeddings and plaintext document chunks are stored on multi-tenant cloud databases (Pinecone, Weaviate Cloud).
  • Prompt Injection & Model Snooping: Queries containing sensitive trade secrets are sent over public networks to LLM inference servers.
  • text
     Traditional Cloud RAG (Vulnerable):
     [Classified Document] ──────(Internet HTTPS)──────> [Cloud API Provider]
                                                         [Multi-Tenant Vector DB]
                                                         [Risk: Egress / Subpoena]
    
     AlaskaVault Air-Gapped Search (Sovereign):
     [Classified Document] ───(Local Bus 300 MB/s)───> [Local Quantized Model]
                                                       [SQLite FTS5 + Local HNSW]
                                                       [Zero Packet Egress]

    2. Dual-Engine Architecture: Sparse + Dense Hybrid Retrieval

    Single-mode search architectures fail in enterprise environments:

  • Dense Semantic Vector Search Alone: Excellent at conceptual understanding ("find documents about employee safety protocols"), but fails catastrophically at exact strings (e.g., serial numbers, hexadecimal error codes, function names like NtQuerySystemInformation).
  • Sparse Lexical Search Alone (BM25): Flawless at exact keywords, but completely blind to synonyms, semantic context, or conceptual rephrasing.
  • AlaskaVault unifies both engines into a concurrent, local-first pipeline:

    text
                                      [Search Query: "Q"]
                                               │
                     ┌─────────────────────────┴─────────────────────────┐
                     ▼                                                   ▼
           [Dense Vector Path]                                 [Sparse Lexical Path]
       Local Quantized Transformer                           SQLite FTS5 BM25 Engine
     (384-dim normalized vector)                               (Term frequency index)
                     │                                                   │
          Cosine Similarity Search                             BM25 Ranking Function
                     │                                                   │
                     └─────────────────────────┬─────────────────────────┘
                                               │
                                [Reciprocal Rank Fusion (RRF)]
                                               │
                             [Unified Ranked Document Results]

    3. Mathematical Foundations

    3.1 Sparse Ranking: SQLite FTS5 BM25

    For exact-token and keyword retrieval, AlaskaVault utilizes an optimized SQLite FTS5 engine implementing the Okapi BM25 ranking function:

    ext{Score}_{ ext{BM25}}(D, Q) = \sum_{i=1}^{N} ext{IDF}(q_i) \cdot rac{f(q_i, D) \cdot (k_1 + 1)}{f(q_i, D) + k_1 \cdot \left(1 - b + b \cdot rac{|D|}{ ext{avgdl}} ight)}

    Where:

  • f(q_i, D) is the term frequency of token q_i in document D.
  • |D| is the length of document D in words, and ext{avgdl} is the average document length across the repository.
  • k_1 = 1.2 (controls term frequency saturation).
  • b = 0.75 (controls document length normalization penalty).
  • ext{IDF}(q_i) = \ln \left( rac{N - n(q_i) + 0.5}{n(q_i) + 0.5} + 1 ight).
  • 3.2 Dense Semantic Ranking: Cosine Similarity in Local Vector Space

    Simultaneously, the query is passed through a local, CPU-optimized transformer model to generate a dense 384-dimensional unit vector ec{u}. Semantic similarity to indexed chunk vector ec{v} is evaluated via dot product:

    ext{Sim}_{ ext{cosine}}( ec{u}, ec{v}) = rac{ ec{u} \cdot ec{v}}{\| ec{u}\| \| ec{v}\|} = \sum_{j=1}^{384} u_j \cdot v_j \quad ( ext{since } \| ec{u}\| = \| ec{v}\| = 1)

    3.3 Fusion: Reciprocal Rank Fusion (RRF)

    To merge the disparate scoring distributions of BM25 (unbounded positive floats) and Cosine Similarity ([-1, 1] floats), AlaskaVault applies Reciprocal Rank Fusion:

    ext{RRF\_Score}(d \in D) = \sum_{m \in \{ ext{Dense}, ext{Sparse}\}} rac{1}{k + r_m(d)}

    Where r_m(d) is the ordinal rank of document d in engine m, and k = 60 is a smoothing constant preventing top-ranked outliers from skewing the combined result.


    4. Local Execution & Zero-Network Guarantee

  • Quantized Inference Engine: AlaskaVault employs 8-bit integer quantization (INT8) running through hardware-accelerated local SIMD instructions (AVX-512 / AVX2 on Intel/AMD, NEON on ARM). Memory footprint is under 180MB RAM with sub-25ms inference latency per query.
  • Strict Socket Isolation: The neural search engine binds exclusively to local IPC handles with zero network socket allocation. Any attempt by third-party plugins to initiate network egress is trapped and terminated.

  • 5. Performance Benchmarks

    Metric AlaskaVault Local Hybrid Cloud API RAG (Pinecone + OpenAI)
    Network Egress 0.00 KB (Zero Packets) 1.8 MB / query (Plaintext)
    Cold Query Latency 18 ms 420 - 1,200 ms
    Availability Under Outage 100% Operational 0% (Fails during cloud downtime)
    Exact Match Precision (IDs) 99.4% 68.2% (Dense hallucination)
    Semantic Concept Recall 94.1% 95.0%

    6. Conclusion

    AlaskaVault's Air-Gapped Hybrid Neural Search proves that enterprises do not need to sacrifice security for artificial intelligence. By combining local vector embeddings with deterministic BM25 lexical indexing, organizations maintain absolute data sovereignty, eliminate cloud subscription fees, and unlock sub-second search speeds on ordinary workstation hardware.

    Deploy Sovereign Defense Infrastructure
    Experience true air-gapped data sovereignty with AlaskaVault & AlaskaSentinel.