A whole category of excellent SaaS products will rent you an AI coworker. Every one of them asks the same price beyond the invoice: your knowledge base, credentials and chat history, hosted on their side. Hedy takes the opposite bet.
Cloud AI employees live in a vendor's tenant, so your knowledge base, API credentials, and chat history sit on their infrastructure and pass through their sub-processors. Hedy inverts custody: it deploys inside your own Docker or Kubernetes cluster, even air-gapped. Documents, embeddings, credentials, and logs never leave your network because there is no outbound path by design. You bring your own model key, including local vLLM or Ollama, and Hedy has zero sub-processors.
| Hedy | Cloud AI employees | |
|---|---|---|
| Where your data lives | Your VPC — or air-gapped | Vendor cloud |
| Source auditable | Yes | Rarely |
| Credentials custody | Never leave your network | Stored vendor-side |
| Model spend | Your keys, metered at cost | Vendor keys, marked-up credits |
| Compliance posture | Your controls, your auditors, our evidence | Vendor SOC2 / DPA paperwork |
| Time to start | ~30 minutes on one VM | Minutes, zero infra |
| Chat platforms | Feishu / Lark / Slack | Usually Slack / Teams only |
Based on public information as of July 2026. Corrections welcome: hello@hedy.one
The custody question is simple: when an AI employee reads your contracts and holds your API keys, whose disk are they on? With cloud AI employees the answer is the vendor's. Your knowledge base is uploaded, your embeddings are stored in their vector database, your chat logs are retained under their policy, and every prompt traverses their sub-processors on the way to a model. You inherit their breach surface and their data-handling terms. Hedy is self-hosted: one docker compose install, roughly 30 minutes, running entirely on infrastructure you own.
Because Hedy runs inside your perimeter, data-residency is a property of the architecture, not a promise in a contract. Ingested documents, generated embeddings, retrieved chunks, and audit records all stay on your volumes. There is no telemetry channel shipping content back to us and there are no sub-processors in the path. You point Hedy at your own model endpoint, your key, your account, and if you require full isolation you run a local model via vLLM or Ollama so that even inference never crosses the network boundary. Air-gapped deployment is supported, licensed offline with Ed25519.
Credentials get the same treatment. Cloud employees ask you to hand write-scoped tokens to their tenant; Hedy keeps secrets in your environment injection and never in the repo. Write actions are default-deny against an allowlist, retrieval is ACL-scoped to the person asking, and approvals are graded L0/L1/L2. So the credential that lets Hedy act is governed where it lives, and the blast radius of any single action is bounded by policy you control, not by trust in an external operator.
Custody also means provability. Every action Hedy takes lands in an append-only audit log you host and cannot silently edit. The evidence gate forces answers to cite their sources verbatim, so you can trace what was read and why. Combined with Feishu/Lark and Slack as first-class surfaces, you get a working AI employee whose entire data footprint, from knowledge to keys to conversation history, stays inside the boundary you already secure.