hedy.one · private-deployment AI employee

One AI employee, doing the work of a whole team.

You were about to add seats to your team. Add one Hedy instead — a single governed AI employee that answers from your knowledge base, ships reports, reviews code and preps meetings. On your own infrastructure. Not another cloud seat, not a meeting note-taker — an employee that holds a job.

$ docker compose up -d  ·  runs air-gapped  ·  your model keys, your data

Runs where you run docker compose helm · kubernetes air-gapped + local models bring your own model keys

Hedy is a private-deployment AI employee: one governed employee that does a whole team's work — answering from your knowledge base with citations, shipping reports, reviewing code, triaging bugs and prepping meetings — deployed on your own infrastructure via Docker, Kubernetes or fully air-gapped. It is not a cloud assistant and not a meeting note-taker; it holds a job, takes initiative, and every action is gated by approvals and an append-only audit trail. The name is the pitch: you need hedy.one.

Built for the teams a cloud AI employee can't serve: where the data can't leave the network — regulated industries, security-first engineering orgs — living in Slack, Teams, Feishu or Lark.

0bytes leave your network (self-hosted)
0automated tests, green
0/17eval gate, evidence-checked
~0 mincompose up to first answer
Runs inside your security boundary Ed25519-signed licences Append-only audit ledger Air-gap ready Read the security model →
Roles

Hire the role your team needs next.

Every Hedy ships the same governed core. The role profile decides what she owns, which tools she carries, and how far her permissions reach.

Engineering

AI Engineering Assistant

  • Context-aware merge request reviews, draft-first
  • Bug triage to suspect files with confidence levels
  • Release-train shepherding and checklists
Knowledge

AI Knowledge Manager

  • Answers company questions with source links
  • ACL-scoped retrieval per asker
  • Flags knowledge gaps instead of guessing
Chief of staff

AI Chief of Staff

  • Pre-read briefs before your key meetings
  • Minutes with owners and deadlines after
  • Daily digests assembled from real data
Research

AI Research Analyst

  • Evidence-first deep research with citation trails
  • Cross-source verification on key claims
  • Reports filed to your doc space, linked back
Product

AI Product Assistant

  • PRDs from a five-question intake
  • Story mode for alignment, engineering mode for build
  • Reviews existing specs against a hard checklist
Operations

AI Operations Coordinator

  • Scheduled jobs with explicit delivery targets
  • Task tracking, reminders and follow-ups
  • Structured handoffs between AI employees

One employee can hold several of these. Roles are profiles over the same core — swap duties without re-hiring, or run multiple employees with separate permissions.

Capabilities

One employee. Job-ready on day one.

Not a bag of prompts — each skill ships with hard rules, tool boundaries and its own acceptance tests.

Answers with receipts

Company questions answered from your knowledge base — hybrid retrieval, ACL-filtered per asker. Every claim carries its source link. No citation, no answer.

Meetings, both ends

A 60-second pre-read brief before you walk in; minutes with owners and action items after. Decisions land in memory, not in a void.

Reports from real data

Daily digests and weekly reports assembled from scripts and APIs — numbers come from command output, never from imagination.

Code, draft-first

Reviews merge requests with project context, triages bugs to suspect files with confidence levels. Writes are allowlisted; merging stays human.

Works the night shift

Scheduled jobs with explicit delivery targets, watchdog-supervised. Missed runs alert — silence is never mistaken for success.

Grows new skills on site

Repeated workflows get distilled into new, versioned skills — verification-first, enabled only after your sign-off. Your Hedy compounds.

How it works

From up -d to first deliverable.

STEP 01

Deploy on your infra

docker compose up -d on a VM, or Helm on Kubernetes. Air-gapped works with local models.

STEP 02

Connect channels & knowledge

Slack, Teams, Feishu or Lark for conversation; Git, Notion, Confluence and your wiki as knowledge sources.

STEP 03

Set the guardrails

Seats, approval tiers, write allowlists, knowledge ACLs. Defaults are deny — you open doors deliberately.

STEP 04

Hedy starts delivering

Cited answers in the group by minute one. Reports, reviews and briefs follow on schedule.

Connectors · MCP

Plug in any tool. Govern every call.

Hedy speaks MCP, so she plugs into the tools your team already runs — GitHub today, more of the ecosystem as it opens up. The difference from a cloud AI employee isn't the length of the connector list. It's that every tool call is governed in code — not asked for politely in a prompt.

Where she lives

Native chat channels — Slack, Microsoft Teams, Feishu and Lark. This is the surface she shows up on: DMs, group threads, approval cards. Separate from the tools she acts on.

What she plugs into

Tool connectors over MCP. GitHub is wired first; Linear and Notion connect through their hosted MCP (OAuth) as they roll out — and the wider MCP ecosystem plugs in the same way. Breadth, like a cloud AI employee.

Governed, not trusted

Every connector runs under the same code-enforced policy — reads open, writes tiered, untrusted servers read-only, egress hard-bounded. The moat isn't the connectors. It's the governance on top.

Tool callWhat Hedy is allowed to do — enforced in code
Read tools (search, fetch, list)Allowed automatically
Low-risk writes (comment, label, status change)Auto-approved, fully audited
High-risk writes (open PR, merge, delete, external comms)Human approval required (L1)
Untrusted / community MCP serversRead-only, never write
Internal-data tools · external-facing employeeBlocked at the egress boundary

Low-risk writes auto-approve so approvals don't become noise; the read-only rule for untrusted servers and the hard egress boundary are supply-chain and exfiltration defenses. Every gate decision and every call lands in the append-only audit ledger — enforced at the boundary, not requested in a prompt.

Governance

Restraint is the product.

Anyone can demo an agent that acts. The hard part is an employee that provably doesn't — doesn't leak, doesn't overstep, doesn't freelance. Every limit below lives in code and config. Prompts are not a security boundary.

17/17eval gate, evidence-checked
0anonymous endpoints
100%actions audited
control ledgerenforced in code
G-01

Deploys inside your walls

Compose or Helm, in your VPC or fully air-gapped. Source available for audit. In self-hosted mode, data never leaves.

G-02

Append-only audit trail

Every action logged with actor, object and reasoning. No update or delete path exists — not even for admins.

G-03

Outward actions gated

Tiered authorization (L0–L2) stored in the database. External posts, spends and commitments wait for a human tap.

G-04

Write access: default deny

Repo writes require an explicit allowlist. Code changes ship as draft PRs; merging is a human verb.

G-05

Red-line conduct tests

We test what Hedy must never say: salary probes, credential requests, injection attempts. Leak checks run in the same eval gate as quality — before every release.

G-06

Scoped knowledge per asker

Retrieval is ACL-filtered server-side by who's asking. External-facing employees are hard-capped to the public layer.

G-07

One metered gateway

Every model call flows through a single quota gateway — budgets, degradation policy and per-employee metering with one source of truth.

A week with Hedy

What the work actually looks like.

Product scenarios, not testimonials — this is the shipped behavior, demoable on day one.

Mon · 09:00

The daily digest posts itself

Yesterday's commits, open approvals and today's schedule — assembled from APIs, delivered to the group, every number traceable.

Tue · meeting ends

Minutes before you're back at your desk

Owners, decisions and deadlines extracted and filed to the doc space. Action items become tracked tasks with reminders.

Wed · MR opened

A review that read the project first

Hedy comments on the merge request with project context — as a draft-first reviewer who cannot merge. Allowlisted repos only.

Thu · someone asks HR

"What's the leave policy?" — answered, cited

Retrieval scoped to what the asker may see. The answer links its source doc; what's ACL-filtered is declared, never leaked.

Fri · 17:00

Weekly report, zero chasing

The week's activity ledger — reviews shipped, questions answered, hours saved — compiled into a report your boss actually reads.

Anytime · red line

"What's Alex's salary?" — declined, logged

Conduct tests ship in the eval gate: salary probes, credential requests and injection attempts are refused and audited.

See the output

What Hedy hands back.

The actual shape of the work — a report, a cited answer, an audit row. Illustrative examples, not customer data.

📊 Daily report · Feishu
Merged4 MRs across billing & api — 2 need release notes
Approvals1 pending > 24h (owner reminded)
Meetings3 sets of minutes filed, 6 action items tracked
Every figure traceable · delivery gated
Cited answer · knowledge base
“New hires accrue 15 days of annual leave, pro-rated in the first year.”
▪ source: HR handbook §3.2
ACL-scoped to the asker · no source, no claim
Evidence gate · grounded, not guessed
Audit ledger · append-only
actoremployee:hedy
actionim.outbound → L1 approval
objectemail draft #4821
ts2026-07-27T09:14:02Z
No update or delete path — for anyone

Illustrative of output format · example data, not a real customer

Compare

Cloud AI employees are easy to hire.
Hard to trust with everything.

SaaS agents ask you to ship your knowledge base, credentials and chat history to their cloud. Hedy takes the opposite bet.

HedyCloud AI employees
Where your data livesYour VPC — or air-gappedVendor cloud
Source auditableYes, by your security teamRarely
Feishu & Lark nativeFirst-class, plus SlackSlack / Teams only
Conduct red-line testingShipped, runs in eval gateUndisclosed
Model keys & token spendYours, metered locallyVendor's, marked up
Pricing modelFlat per-seat licenceUsage credits

Hedy column shows Self-hosted / BYO mode, the flagship deployment. Managed mode routes model traffic through Hedy's gateway and bills usage credits — see pricing below.

Pricing

Two ways to hire.

Run Hedy on your own infrastructure with your own model keys — a flat licence, data that never leaves, no sub-processors. Or let us host the model layer and start in minutes, billed like a cloud service. Same employee, same governance; you choose where the models run and who sees the traffic.

Self-hosted · your infrastructure · your keys · data never leaves

Pilot
$500/mo
one AI employee · billed annually
  • Full skill set, eval-gated
  • Docker Compose deployment
  • Feishu / Lark / Slack channels
  • Full governance ledger (G-01 – G-07)
  • Email support
Start a pilot
Team
$1,900/mo
up to 5 AI employees · billed annually
  • Everything in Pilot, per employee
  • Helm / Kubernetes, HA deployment
  • Role profiles & egress controls
  • Security review support & DPA
  • Priority support
Talk to us
Enterprise
Custom
unlimited employees · from $60k/yr
  • Unlimited AI employees
  • Air-gapped with local models
  • Dedicated onboarding & custom skills
  • SLA + named support
  • Your paper, your procurement
Talk to us

Managed · we host the model layer · start in minutes

Managed
from $99/mo + usage
models & compute included · credits, top up anytime · no keys to configure

Prefer to skip infrastructure? We run the model gateway; you hire an employee in minutes and pay for what it does, billed like a cloud service. Best for teams where cloud AI is already acceptable.

Lower data-residency, by design. In Managed mode, model traffic flows through Hedy's gateway — so it is not air-gapped and not sub-processor-free: Hedy and the model provider process that traffic. The gateway stores metering metadata (tokens, cost, model, latency) and your credit ledger, never prompt or response content; knowledge base, memory and audit logs stay in your own deployment. If your data can't leave the network, choose Self-hosted above. We'll tell you straight which one fits.

Start managed

Why per employee, and why your choice on models? An AI employee that does a whole team's work shouldn't cost more every time it works — on Self-hosted the meter belongs to you (per-employee pricing even drops as you add seats, $500 → $380 on Team). Managed exists for speed, not for us to mark up your tokens quietly — and we're upfront that it trades away data residency. Most security-first teams start Self-hosted; that's the point of Hedy.

FAQ

Frequently asked questions.

How is Hedy different from ChatGPT or a copilot?
Copilots wait for prompts. Hedy holds a job: she keeps persistent, company-scoped memory, runs scheduled work around the clock, joins your group chats as a colleague, and ships deliverables — reports, briefs, reviews — without being asked each time. And unlike either, she runs on your infrastructure.
Which chat platforms does Hedy work in?
Feishu and Lark are first-class — DM and group chat, approval cards, cloud-doc filing, org-directory awareness. Slack is supported. All channels are allowlist-gated: Hedy only talks where you've put her.
Can Hedy connect to our tools — GitHub, Linear, Notion?
Yes, over MCP — the open protocol those tools expose. GitHub is wired first; Linear and Notion connect through their hosted MCP (OAuth) as they roll out, and the wider ecosystem plugs in the same way. The difference from a cloud AI employee is what happens on every call, enforced in code: read tools run automatically, low-risk writes are auto-approved and fully audited (no approval fatigue), high-risk writes — open a PR, merge, delete, anything outbound — wait for human approval, and an MCP server you haven't vetted is granted read-only, never write. An external-facing employee can't reach internal-data tools at all. Every call lands in the append-only audit ledger.
Where does our data live?
On your machines. Hedy deploys into your VPC via Docker Compose or Helm — or fully air-gapped with local models. Knowledge base, memory, audit logs and metering records stay in your Postgres in both modes. On Self-hosted, nothing phones home; there is no home to phone. On Managed, exactly one thing leaves: model calls route through our gateway, which keeps metering metadata (tokens, cost, model, latency) — never prompt or response content.
Which models does Hedy use, and can I skip configuring keys?
Two options. Self-hosted: bring your own model keys — international providers (Anthropic- or OpenAI-compatible APIs) or Chinese ones such as DeepSeek, Qwen, Kimi and GLM — including local vLLM or Ollama for air-gapped sites — every call flows through your own metering gateway, data never leaves. Managed: we host the model layer so there are no keys to configure and you start in minutes, billed like a cloud service. In Managed mode, Hedy and the model provider are sub-processors for model traffic only: our gateway stores metering metadata (tokens, cost, model, latency), never your prompts or replies, and your knowledge base, memory and audit logs still live in your own deployment. It isn't air-gapped, and security-first teams choose Self-hosted.
How long does deployment take?
A pilot is one VM and about 30 minutes: docker compose up -d, connect a channel, point a knowledge source. Kubernetes via Helm for production. We ship a deployment guide and backup/restore/upgrade scripts.
What happens when Hedy gets something wrong?
Four nets, in order: answers must cite sources (no citation, no claim); an evidence-checked eval gate runs before every release; outward actions wait for human approval; and everything lands in an append-only audit trail — so wrong is visible, bounded and correctable, not silent.
Can Hedy act without asking?
Only inside lines you drew. Autonomy is tiered per action class (L0 auto / L1 approve / L2 forbidden) and stored in the database, not in a prompt. Scheduled jobs must name their delivery target explicitly — "send it to whoever asked last" is banned by design.
What about prompt injection and data leaks?
Treated as a release blocker, not a disclaimer: red-line conduct tests (salary probes, credential requests, injection attempts) run in the same gate as quality evals. Retrieval is ACL-filtered server-side. External-facing employees are hard-capped to public knowledge. Sensitive calls never silently degrade to weaker models.
Does Hedy replace my team?
No — she takes the load nobody wants: the digest, the minutes, the chasing, the first-pass review. Your team keeps judgment, taste and the merge button. Customers keep a human-only channel too; we recommend it in the deployment guide.
hedy.one

Hire your first employee
that never phones home.

A 30-minute demo on our infrastructure — then the same stack, deployed on yours.

her own name, account and memory cited answers by minute one works your night shift approvals stay human every action audited your infra, your keys, your data