Wait — everything is self-hosted now?
Yes. The whole stack runs in your cloud account, on every tier. The only choice is who operates it: Self-Host, where you run the one-command deploy yourself, or Done-for-You, where we deploy and operate it inside your account. There is no shared SaaS that holds your data — that's the point.
What's the difference between Self-Host and Done-for-You?
Same software, same bytes — different labor. Self-Host is a versioned set of Docker images plus a one-command deploy script you run against your own cloud; you bring your own Gemini API key. Done-for-You is us doing the deploy, the upgrades, and the on-call ops inside your account, with the Gemini key included and an SLA. Your IAM credentials stay in a Vault in your infrastructure either way.
If it's in our cloud, how do you bill per employee?
Headcount is self-reported from your HRIS and trued up annually in your order — the same honor-plus-contract model used by self-managed enterprise software everywhere. Contractors and part-time staff in HRIS count; people you've already terminated don't. No per-action fees: you pay for the surface area under management, not each provision, move, or revocation.
Do you ever see our data or credentials?
No. Every deployment runs in infrastructure you own, and long-lived tokens stay in a Vault we deploy into your account. On Done-for-You we have operational access to run and upgrade it — and you can revoke that access at any time. We never hold your credentials in our own infrastructure.
Do you resell or mark up the portal APIs we connect?
No. The deployment calls Okta, Microsoft Graph, Salesforce, and the rest using your credentials, from your own cloud. We pay nothing to them and neither do you for the calls. Your existing license agreements are unchanged.
How do you handle the "AI got it wrong" case?
The AI only parses — it never decides. Every action goes through deterministic risk scoring and OPA policy. Anything above 0.75 is routed to HITL by default, and every executed action is reversible within its grace period (Salesforce: 30 days; Okta/M365: immediate reactivation via audit replay).
What's the contract look like?
Self-Host is an annual license with image-registry access. Done-for-You adds a one-time setup fee and an operations agreement with an SLA. Enterprise is a one- to three-year MSA with a data processing addendum and optional BAA. All tiers include a mutual NDA and our incident-response commitment. SOC 2 / ISO 27001 controls are implemented; the certifications are on our roadmap and not yet held.
Is there a pilot?
Yes — the first design partners each quarter get a hands-on pilot. Request a pilot.