Log

How it works

One record shared by every AI you use, where it lives, and the three ways you can run it.

VaultHelm sits between the AI you already use and the things you actually care about. Your AI carries on doing what it’s good at. Everything it does gets written down, and anything that matters has to come past you first.

It’s just files. That’s on purpose.

Everything VaultHelm keeps is stored as ordinary text documents. Not a database, not a format only we can read. You could open any of it in Notepad tomorrow.

Right now we host that for you — your own separate copy, with its own files and its own key. It is never a shared system with several customers’ work in one pile. And because it is only a folder of text files, you can take a copy of the whole thing, full history included, whenever you ask.

Underneath, every version of every file is saved automatically, so nothing is ever really deleted — you can always go back and see what something looked like last month. In our own system that’s over thirteen thousand saved versions since April.

This is deliberate, and it is the answer to the obvious question about letting someone else hold your record. If VaultHelm vanished tomorrow you would still have a folder of text files that opens on any computer, with its full history intact. A record you cannot read without the company that sold it to you was never really your record.

One record, every AI you use

This is the part that doesn’t exist anywhere else, so it’s worth being clear about.

Every assistant keeps its own memory, and none of them share. What you told one is invisible to the next. Each vendor is quietly building a silo, and the longer you use one the more expensive it becomes to leave.

VaultHelm sits underneath all of them instead. Your record and your permissions live in one place that belongs to you, and every assistant you connect reads and writes that same record. Ask any of them what happened on Tuesday and you get the same answer.

Be clear about what does and does not move. Nothing is piped between AI companies. Your conversation with one is never handed to another, and we are not brokering your data between vendors. What carries over is the written record on your side, and only what you chose to file into it. Each assistant reads that record the same way it would read any document you gave it.

In practice that means:

  • Use the right tool for the job. One assistant for writing, another for code, whichever is on your phone at the time. Each reads the same filed record when it starts, so none of them begins cold.
  • Approvals travel as well as memory. A request raised by one AI can be approved from a different one entirely. Proposed at your desk in the morning, approved from your phone that evening, in another app.
  • A better model costs you nothing. When something new launches you just try it. Everything you’ve built up carries over, because it was never stored inside the AI to begin with.

What makes this possible is that the AI tools have agreed on a common way to plug into outside systems. It has a name — MCP — and Grok, Claude and ChatGPT all speak it. So VaultHelm doesn’t have to integrate with each AI separately; it sits on the standard and they connect to it. Anything that speaks MCP works, including tools that don’t exist yet.

Fourteen different AI-and-device combinations have already gone through ours.

One word at the end

When you finish working, you type one word. That’s the whole ritual. VaultHelm then:

  1. Keeps the conversation exactly as it happened, word for word.
  2. Sorts it out — if you worked on three different customers today, it splits it into three.
  3. Files each piece under the right customer’s history.
  4. Closes off whatever job you were working on.
  5. Tells you what it did, including how much of your work it accounted for.

That last one matters more than it sounds. Summaries lose things. So before VaultHelm tells you it saved successfully, it checks how much of your actual work made it in. If too much went missing, it keeps the whole conversation word for word instead of a summary. It isn’t allowed to say “done” without doing that check.

And if your connection drops halfway through, just say the word again. Repeating yourself never creates a duplicate — it only fills in what didn’t make it the first time.

Finding it again

Weeks or months later, you ask a normal question — “what did we do for the Henderson job in March?” — and you get three things:

  1. The entry. The short version: who it was for, when, what it was about.
  2. The write-up. What was actually done, in that customer’s own history.
  3. The original. The raw conversation it came from, untouched.

You can always get to that third one. If the summary got something wrong you can correct it, and VaultHelm will even learn the correction so it files things properly next time. But the original conversation underneath is never rewritten. Corrections change the index, never the record.

Asking before acting

This is the part people get wrong about AI, so it’s worth being precise.

VaultHelm doesn’t ask your AI to be careful. Nobody writes it a polite instruction and hopes for the best. Instructions can be argued with — a cleverly worded document, a malicious email, or just an AI having an off day can talk a model out of almost any rule it was given.

Instead, the limits live on the server, outside the conversation entirely. Your AI can be talked into agreeing to anything at all, and it still cannot act on it, because the thing it would need simply is not available to it.

A rule the AI could talk itself out of was never a rule. So we didn’t write one.

In practice this means two things:

  • It can only see what you switched on. The list of things your AI is shown and the list of things it can actually do are the same list. There’s no hidden menu to discover and no way to ask for more.
  • Anything that matters waits for you. Your AI can read and draft freely. When it wants to do something real, that request lands in front of you — what it wants to do, why, and which machine it came from — and sits there until you answer.

You say yes, no, later, or pass it to someone else, whenever you get to it. Nothing is pressuring you to approve something at eleven at night because a chat window is waiting. In our own system, 281 requests have gone through this. Three were turned down. Some are still sitting there, which is exactly what should happen.

Your copy is separate

Every customer gets their own separate installation — their own files, their own history, their own key. Nobody’s records sit in a shared pile with anybody else’s, and there’s no central system holding everyone’s work. Hosting several customers does not mean mixing them.

Updates get tested first and then sent out deliberately. Nothing changes underneath you overnight because someone pushed a button somewhere else.

What runs where — plainly

  • In your copy, which we host: your records, your file history, your search, the list of what your AI is allowed to do, the log of what it did, and the queue of things waiting for your approval.
  • Somewhere else entirely: the AI itself. The thinking is done by Grok, Claude or ChatGPT on their servers, using the account you already pay for.

We say that plainly because of what the alternative actually costs. Running the AI itself in-house means buying serious hardware and accepting a noticeably weaker model. That’s a legitimate choice for some organisations and we’ll happily quote it — but it’s a different shape of project, and a company that blurs that line is hoping you won’t ask.

Three ways to run it

  1. We host it — the normal way, and where we’d start you. Your own separate copy, nothing to install, nothing for you to keep running. Your AI is Grok, Claude or ChatGPT on the account you already have.
  2. On your own equipment. Perfectly possible, but a custom deployment rather than an off-the-shelf install. Sensible if you already run your own servers, or a policy says the record stays in the building. Your AI is still Grok, Claude or ChatGPT.
  3. On your own equipment, with the AI in-house too. Fully self-contained, nothing leaving your network. This needs serious hardware — proper GPUs, not a spare office machine — and the model you end up with will be noticeably weaker than the commercial ones. We’ll be straight with you about that trade before you spend anything on it.

Most people want the first one, and it’s the fastest to get running. Either way, using it is one word at the end of your day.