Log

Control

What your AI is allowed to do, where the limits live, and who runs it.

Asking before acting

This is the part people get wrong about AI, so it’s worth being precise.

VaultHelm doesn’t ask your AI to be careful. Nobody writes it a polite instruction and hopes for the best. Instructions can be argued with — a cleverly worded document, a malicious email, or just an AI having an off day can talk a model out of almost any rule it was given.

Instead, the limits live on the server, outside the conversation entirely. Your AI can be talked into agreeing to anything at all, and it still cannot act on it, because the thing it would need simply is not available to it.

A rule the AI could talk itself out of was never a rule. So we didn’t write one.

In practice this means two things:

  • It can only see what you switched on. The list of things your AI is shown and the list of things it can actually do are the same list. There’s no hidden menu to discover and no way to ask for more.
  • Anything that matters waits for you. Your AI can read and draft freely. When it wants to do something real, that request lands in front of you — what it wants to do, why, and which machine it came from — and sits there until you answer.

You say yes, no, later, or pass it to someone else, whenever you get to it. Nothing is pressuring you to approve something at eleven at night because a chat window is waiting. In our own system some requests have been sitting there for weeks, which is exactly what should happen — a queue that never has anything waiting in it is a queue nobody is really using.

Your copy is separate

Every customer gets their own separate installation — their own files, their own history, their own key. Nobody’s records sit in a shared pile with anybody else’s, and there’s no central system holding everyone’s work. Hosting several customers does not mean mixing them.

Updates get tested first and then sent out deliberately. Nothing changes underneath you overnight because someone pushed a button somewhere else.

What runs where — plainly

  • In your copy, which we host: your records, your file history, your search, the list of what your AI is allowed to do, the log of what it did, and the queue of things waiting for your approval.
  • Somewhere else entirely: the AI itself. The thinking is done by Grok, Claude or ChatGPT on their servers, using the account you already pay for.

We say that plainly because of what the alternative actually costs. Running the AI itself in-house means buying serious hardware and accepting a noticeably weaker model. That’s a legitimate choice for some organisations and we’ll happily quote it — but it’s a different shape of project, and a company that blurs that line is hoping you won’t ask.

Eight questions worth asking

Ask these about whatever you are using today. The difference is not a better answer — it is whether there is an answer at all.

Question Just using chat With VaultHelm
What did we do for this customer in March? Scroll back through old chats and hope Ask, and get the write-up plus the original conversation
Who approved that change? Nobody. It just happened Written down as it happened — who moved it across, when, and what they were looking at
Can it change something important on its own? Whatever you gave it access to No. It writes down what it wants and waits for you
My connection dropped — did it save? Run it again and hope you don’t double up Ask it. Repeating yourself never creates a duplicate
What is my AI actually allowed to do? Hard to say, and it may find more by trying A list you chose — what it can do, and what it can open. Off the list isn’t refused; it isn’t there
Could someone trick it into ignoring the rules? Yes — instructions in a document or email can override it They can change its mind. They can’t change what it’s able to reach
Where is all of this kept? In a shared system, for as long as they choose to keep it Your own separate copy, as plain files — and yours to take
What if I switch, or use two AIs? Start over. Each one’s memory is its own Each reads the same record you own, so none of them starts cold

Try this on whatever you use now. Ask it what it did last Tuesday. Not what ran — what was decided. Who approved it, what they were looking at when they decided, and when. Most tooling answers the first question well and has no idea about the second, because nothing ever recorded that a decision happened at all.

How it runs

We host it. That is the only way it ships today, and we would rather say so than
present a menu.
You get your own separate copy — its own files, its own key,
never pooled with another customer’s work. There is nothing to install and nothing for you
to keep running. Your AI stays Grok, Claude or ChatGPT on the account you already pay for.

Two things people ask for that we do not sell, answered straight rather than
quoted:

  • Running it on your own servers. Not an off-the-shelf install and not a
    product we offer today. If your policy requires the record to stay in your building, tell us
    and we will talk honestly about whether we can get there — but we are not going to take
    a deposit against it.
  • Running the AI itself inside your network. Technically possible, and the
    honest answer is still no: it needs real GPU hardware and leaves you with a markedly weaker
    assistant than the one you already have. We would be charging you to make the product worse.

Using it is one word at the end of your day.