Offline devices: The only thing that goes away when a device can’t connect to the cloud is the update and management cycle. Your code continues to execute, endpoints and requests across the local subnet continue to work fine.
Network sniffing: This sort of conversation is one we’re taking seriously, and we will soon have a couple of big milestones done for making this kind of conversation with your boss nice and easy. The first is a security white-paper which will set out our philosophy and practices regarding security. The second is that all of the code executing on your device will be open source, so therefore can be verified.
In the mean time an exercise for the careful would be to monitor all of the communications from the device, and scrutinise the OS .img file downloaded.