Flagship · the AI wedge

Your AI. Your keys.
Works offline.

The admin picks the engine. Native local models by default, running with the internet unplugged. Your own cloud key when you want more power, with automatic fallback to native the instant the cloud fails. The intelligence lives in your building, on your terms.

Native by default · your key optional · fallback always on

The problem with renting

Rented intelligence can be switched off.

Almost every AI feature you have seen is a tenant's deal: it runs on someone else's servers, under someone else's pricing, reachable only while the line stays up. A price hike, a revoked key, an outage or a border is all it takes. Own the engine and none of that can reach you.

Rented AI
  • Their pricing, changes without you
  • Their key, revocable at any time
  • Their servers, your data over there
  • Line drops? Everything stops
Owned AI
  • No meter, native calls are free
  • Your keys, encrypted, capped, yours
  • Your servers, data never leaves
  • Line drops? It keeps thinking

Why own it

The intelligence lives in your building, on your terms.

Air-gapped safe

Behind a DMZ or fully off the grid, the AI still works. Your data never leaves the room it is in.

Zero token bills

Native models cost nothing per call. Use AI as much as you like without watching a meter tick.

One setting, everywhere

Pick the engine once in global settings. Every feature that uses AI inherits it. No wiring, no repeats.

One setting, everywhere

One switch. Native by default, your key when you want it.

Pick the engine once in global settings and every feature inherits it, no wiring, no repeats. Point it at a cloud provider with your own key for more power, and the moment that key caps out or the line drops, it falls back to native. Nobody gets paged.

Global settings · AI engine

Every AI feature inherits the setting:

Rewrite native Chatbot native Journeys native RAG native Spam check native · locked
Native is the default, always available, always free.

The actual setting

Downstream

Everything downstream just calls it.

Rewrite, translate, chatbot, journeys, campaign copy, RAG: none of them know or care which engine sits behind the one interface. Change the engine and they all follow, together, instantly.

one interface

The guard that never phones home

Every message checked. Spam flagged, not blocked.

Spam-checking is the one job too important to outsource. It runs native, on the message hot path: fastText and rules checking every message in about a tenth of a millisecond, flagging what looks like spam without ever blocking a send or making a network call.

incoming “Your OTP is 4821” “WIN a FREE $$$ prize, click now!!” “Order #1024 shipped 🎉”
native spam check ~0.1 ms · no network hop
passes through OTP · delivered Order · delivered flagged as spam “WIN a FREE…” · flagged, not blocked

Flag, don't block: you keep the final call, and the check never leaves the box.

Under the hood

For the engineer in the room.

Present, not primary: the specifics a technical evaluator will want to confirm.

One internal interface, OpenAI-compatible

Built to the /v1/chat-completions shape, so native, OpenAI and most providers work through the same contract. One extra adapter covers Anthropic.

Embeddings are a separate setting

The embeddings model is chosen independently from the chat model: swap either without touching the other.

Spam is native, always

fastText and rules, on the hot path, flag-don't-block. Never an LLM, never a network hop.

Keys are encrypted at rest

Third-party keys are encrypted, redacted in logs, and capped. Set a hard cost cap per engine: hit it, and it falls back to native.

Assistive, not autonomous

Campaigns stay human-approved. RAG answers carry a “not in the documentation” guardrail instead of inventing.

Runs on commodity hardware

Native serves through llama.cpp / Ollama (e.g. Phi-4-mini) on plain CPU: built for offline, edge and low-concurrency boxes.

Before you ask

What hardware does native AI need?

Native runs on commodity server hardware: no GPU farm required for the assistive tasks (rewrite, translate, chatbot, spam). Sizing guidance is in the platform docs.

Which cloud providers can I use?

Any OpenAI-compatible provider through the standard interface, plus Anthropic via its adapter. You bring the key; you stay in control of the account and the spend.

What happens when a key hits its cost cap?

The engine falls back to native automatically. The feature keeps working. You get your data, never a broken screen.

Can the AI leak my data to a vendor?

On native, nothing leaves your servers. On cloud, only what you choose to send goes out, under your own account, and you can run fully native if you never want that.

Own the intelligence.

Your AI, your keys, on servers you own, that keeps thinking with the world switched off.