Skip to content
RO
← All writing

A private AI assistant that runs on your own server

  • ai
  • self-hosted
  • privacy
  • infrastructure

Most AI tools want your work on somebody else’s computer. Your documents, your client list, the half-finished quote you abandoned on Tuesday: all of it goes to a data centre you have never seen, under terms nobody in your office has read.

This one runs on a machine you own, in your building.

What it does

“AI assistant” means nothing on its own, so here is the actual list.

It watches your systems. Uptime, load, memory, disk, and whether your sites are answering, all on one screen. A disk quietly filling up becomes a sentence you read over coffee instead of a phone call from a customer on Monday morning. The routine checks nobody remembers to do run whether anyone remembers or not: did last night’s backup actually finish, is a certificate about to expire, did anything restart on its own at four in the morning.

It writes your morning. A briefing lands before the working day starts. What changed overnight, what needs a decision from you, what can wait until Thursday. You choose the time and you choose what goes in it.

Your inbox gets the same treatment. Not replies written on your behalf, but an honest answer to the only question that matters at nine o’clock: which six of these ninety emails actually need me today, and what is each one asking for.

It answers questions about your own files. Point it at a folder and ask. Contracts, quotes, notes, meeting minutes, whatever you have handed it. It sees what you give it access to and nothing else, and that list is agreed in writing before it is switched on.

It does the jobs you would otherwise do by hand. Pull a report, run a check, restart a service that has fallen over. How far that goes is your decision: it can be limited to reading and reporting only, which is how most firms start, or allowed to act on machines you name.

It remembers. Each night it reads the day back and works out what is worth keeping. This is where most assistants quietly fail. In one recent run it read 230 messages across 125 conversations and wrote down exactly one thing — because restraint is harder than recall, and an assistant that files everything gets slower and more confused every week it runs. Everything it has ever noted has to be carried into every future answer.

You can reach it from your phone through a messaging app, if that suits how you work. One caveat worth stating plainly, because it is the only one: those messages travel through the messaging service like any other message you send. Leave that feature off and the assistant never connects to anything beyond your walls.

How it is locked down

The hard part was never the intelligence. It was making sure nothing could reach it.

The service listens only on the machine itself. No port is open to the internet, there is no account to sign into, nothing is published and there is nothing for a scanner to find. When remote support is needed, the machine dials out rather than waiting for anything to dial in, so your firewall never gains a hole. The disk is encrypted, which means a stolen machine is not a reportable breach.

Your files, and everything the assistant has learned about your business, sit on hardware you own in a building you have the keys to.

Two things that were harder than expected

The useful part of any write-up is the mistakes.

A fallback that guarded the wrong operation. One part of it was built to fall back from the graphics card to the processor if the card failed. The fallback never fired, because loading the model onto the card succeeded and it was only the actual work afterwards that failed. A fallback has to guard the thing that breaks, not the step before it.

Silence that looked like success. A rewrite of the interface deleted an element that the startup code still wrote to. That write ran first, threw immediately, and everything after it never happened, while the screen carried on looking perfect. Nothing was logged, so nothing was noticed. Every component writes to a readable log now.

The honest trade

An assistant that keeps your data in your building runs an open-weights model on your hardware, and those models are less capable than the big commercial services. On summarising your systems, drafting, and answering questions about your own documents, the difference is small. On open-ended reasoning it is noticeable.

You would see the actual model, on the actual hardware, before committing to anything. That demonstration is part of the first day, and it exists so nobody buys a disappointment.

Who it suits

Firms holding client data they are not allowed to send anywhere. Solicitors, clinics, accountants, anyone working to an NHS contract. Anyone who has opened a supplier’s sub-processor list and gone quiet.

What it costs

A working system on your own hardware, configured around your systems and handed over documented, starts at £6,500 plus the machine. A paid discovery day comes first and comes off the build, so you see it running before you decide.

Ask what leaves your network. It is a short list, and the logs are yours to read.

Get in touch.