You were about to add seats to your team. Add one Hedy instead — a single governed AI employee that answers from your knowledge base, ships reports, reviews code and preps meetings. On your own infrastructure. Not another cloud seat, not a meeting note-taker — an employee that holds a job.
$ docker compose up -d · runs air-gapped · your model keys, your data
Hedy is a private-deployment AI employee: one governed employee that does a whole team's work — answering from your knowledge base with citations, shipping reports, reviewing code, triaging bugs and prepping meetings — deployed on your own infrastructure via Docker, Kubernetes or fully air-gapped. It is not a cloud assistant and not a meeting note-taker; it holds a job, takes initiative, and every action is gated by approvals and an append-only audit trail. The name is the pitch: you need hedy.one.
Built for the teams a cloud AI employee can't serve: where the data can't leave the network — regulated industries, security-first engineering orgs — living in Slack, Teams, Feishu or Lark.
Every Hedy ships the same governed core. The role profile decides what she owns, which tools she carries, and how far her permissions reach.
One employee can hold several of these. Roles are profiles over the same core — swap duties without re-hiring, or run multiple employees with separate permissions.
Not a bag of prompts — each skill ships with hard rules, tool boundaries and its own acceptance tests.
Company questions answered from your knowledge base — hybrid retrieval, ACL-filtered per asker. Every claim carries its source link. No citation, no answer.
A 60-second pre-read brief before you walk in; minutes with owners and action items after. Decisions land in memory, not in a void.
Daily digests and weekly reports assembled from scripts and APIs — numbers come from command output, never from imagination.
Reviews merge requests with project context, triages bugs to suspect files with confidence levels. Writes are allowlisted; merging stays human.
Scheduled jobs with explicit delivery targets, watchdog-supervised. Missed runs alert — silence is never mistaken for success.
Repeated workflows get distilled into new, versioned skills — verification-first, enabled only after your sign-off. Your Hedy compounds.
up -d to first deliverable.docker compose up -d on a VM, or Helm on Kubernetes. Air-gapped works with local models.
Slack, Teams, Feishu or Lark for conversation; Git, Notion, Confluence and your wiki as knowledge sources.
Seats, approval tiers, write allowlists, knowledge ACLs. Defaults are deny — you open doors deliberately.
Cited answers in the group by minute one. Reports, reviews and briefs follow on schedule.
Hedy speaks MCP, so she plugs into the tools your team already runs — GitHub today, more of the ecosystem as it opens up. The difference from a cloud AI employee isn't the length of the connector list. It's that every tool call is governed in code — not asked for politely in a prompt.
Native chat channels — Slack, Microsoft Teams, Feishu and Lark. This is the surface she shows up on: DMs, group threads, approval cards. Separate from the tools she acts on.
Tool connectors over MCP. GitHub is wired first; Linear and Notion connect through their hosted MCP (OAuth) as they roll out — and the wider MCP ecosystem plugs in the same way. Breadth, like a cloud AI employee.
Every connector runs under the same code-enforced policy — reads open, writes tiered, untrusted servers read-only, egress hard-bounded. The moat isn't the connectors. It's the governance on top.
| Tool call | What Hedy is allowed to do — enforced in code |
|---|---|
| Read tools (search, fetch, list) | Allowed automatically |
| Low-risk writes (comment, label, status change) | Auto-approved, fully audited |
| High-risk writes (open PR, merge, delete, external comms) | Human approval required (L1) |
| Untrusted / community MCP servers | Read-only, never write |
| Internal-data tools · external-facing employee | Blocked at the egress boundary |
Low-risk writes auto-approve so approvals don't become noise; the read-only rule for untrusted servers and the hard egress boundary are supply-chain and exfiltration defenses. Every gate decision and every call lands in the append-only audit ledger — enforced at the boundary, not requested in a prompt.
Anyone can demo an agent that acts. The hard part is an employee that provably doesn't — doesn't leak, doesn't overstep, doesn't freelance. Every limit below lives in code and config. Prompts are not a security boundary.
Compose or Helm, in your VPC or fully air-gapped. Source available for audit. In self-hosted mode, data never leaves.
Every action logged with actor, object and reasoning. No update or delete path exists — not even for admins.
Tiered authorization (L0–L2) stored in the database. External posts, spends and commitments wait for a human tap.
Repo writes require an explicit allowlist. Code changes ship as draft PRs; merging is a human verb.
We test what Hedy must never say: salary probes, credential requests, injection attempts. Leak checks run in the same eval gate as quality — before every release.
Retrieval is ACL-filtered server-side by who's asking. External-facing employees are hard-capped to the public layer.
Every model call flows through a single quota gateway — budgets, degradation policy and per-employee metering with one source of truth.
Product scenarios, not testimonials — this is the shipped behavior, demoable on day one.
Yesterday's commits, open approvals and today's schedule — assembled from APIs, delivered to the group, every number traceable.
Owners, decisions and deadlines extracted and filed to the doc space. Action items become tracked tasks with reminders.
Hedy comments on the merge request with project context — as a draft-first reviewer who cannot merge. Allowlisted repos only.
Retrieval scoped to what the asker may see. The answer links its source doc; what's ACL-filtered is declared, never leaked.
The week's activity ledger — reviews shipped, questions answered, hours saved — compiled into a report your boss actually reads.
Conduct tests ship in the eval gate: salary probes, credential requests and injection attempts are refused and audited.
The actual shape of the work — a report, a cited answer, an audit row. Illustrative examples, not customer data.
Illustrative of output format · example data, not a real customer
SaaS agents ask you to ship your knowledge base, credentials and chat history to their cloud. Hedy takes the opposite bet.
| Hedy | Cloud AI employees | |
|---|---|---|
| Where your data lives | Your VPC — or air-gapped | Vendor cloud |
| Source auditable | Yes, by your security team | Rarely |
| Feishu & Lark native | First-class, plus Slack | Slack / Teams only |
| Conduct red-line testing | Shipped, runs in eval gate | Undisclosed |
| Model keys & token spend | Yours, metered locally | Vendor's, marked up |
| Pricing model | Flat per-seat licence | Usage credits |
Hedy column shows Self-hosted / BYO mode, the flagship deployment. Managed mode routes model traffic through Hedy's gateway and bills usage credits — see pricing below.
Run Hedy on your own infrastructure with your own model keys — a flat licence, data that never leaves, no sub-processors. Or let us host the model layer and start in minutes, billed like a cloud service. Same employee, same governance; you choose where the models run and who sees the traffic.
Self-hosted · your infrastructure · your keys · data never leaves
Managed · we host the model layer · start in minutes
Prefer to skip infrastructure? We run the model gateway; you hire an employee in minutes and pay for what it does, billed like a cloud service. Best for teams where cloud AI is already acceptable.
Lower data-residency, by design. In Managed mode, model traffic flows through Hedy's gateway — so it is not air-gapped and not sub-processor-free: Hedy and the model provider process that traffic. The gateway stores metering metadata (tokens, cost, model, latency) and your credit ledger, never prompt or response content; knowledge base, memory and audit logs stay in your own deployment. If your data can't leave the network, choose Self-hosted above. We'll tell you straight which one fits.
Start managedWhy per employee, and why your choice on models? An AI employee that does a whole team's work shouldn't cost more every time it works — on Self-hosted the meter belongs to you (per-employee pricing even drops as you add seats, $500 → $380 on Team). Managed exists for speed, not for us to mark up your tokens quietly — and we're upfront that it trades away data residency. Most security-first teams start Self-hosted; that's the point of Hedy.
A 30-minute demo on our infrastructure — then the same stack, deployed on yours.