Secure AI for local business

Everyone is
selling you AI.
Nobody is
installing it.
We do.

In the cloud on the frontier models, or on a machine in your building that never phones home.

Agents wired into the tools you already own, on the frontier models or on a private box in your building. Ten business days, fixed price, written security audit.

agents/front-desk · run 0f21c4
+0.0s
bookaskescalateCall inTwilio VoiceTranscribestreaming STTAI AgentTools AgentSwitchmode: RulesCalendaravailabilityHold slotidempotentConfirmvoice + SMSAnswerknowledge baseWrite CRM+ transcriptRing humanescalationModelMemorycaller historyCalendarCRM

01/1414 nodes · whole workflow

execution trace0/14

p50 latency

tool calls

0

tokens

0

cost

handoff

watching

0
business days to production
0
of your data on our servers
1
page to sign, fixed scope

Two ways to run it

The frontier models, or a box in your building.Or both.

Every build runs one of two ways, and the agents are identical either way. The only decision is where the model lives and where your data is allowed to go. We will tell you which one you actually need on the first call.

In the cloud

The frontier models, on your keys.

GPT, Claude, Grok and Gemini through one gateway you own. The best model for each job, automatic failover when a provider is down, spend caps, and every call logged. You pay the providers directly. No markup, no middleman account, no lock-in to whichever lab is winning this quarter.

  • OpenAI
  • Anthropic
  • xAI
  • Gemini

For companies that want the strongest models and are fine with provider terms.

Included in every build

In your building

A private AI that never phones home.

A Mac mini or a Ryzen AI Max box on your own network, running an open-weight model in the 27B to 70B class. The same agents, the same tools, and not one byte of client data leaves the building. For law, medical, the trades, and anyone who has been burned once.

  • Hardware supplied, installed and hardened
  • Open-weight model tuned to your work
  • Keeps working when the internet doesn't
  • The same written security note, one line shorter: nothing leaves
  • Qwen
  • Llama
  • Ollama
  • Apple silicon

Quick Win pricing. Hardware is yours outright.

From $6,500 installed · the kits 

Or both

Most companies end up hybrid. Client files and anything regulated stay on the box in the back office; everything else uses the frontier. One system, one audit log, and the agents cannot tell the difference.

Ask which one you need

Runs inside the tools you already pay for

QuickBooksTwilio Google CalendarHubSpotStripe Shopify SlackXero SalesforceCal.com GmailSquare Google Sheets SupabaseOpenAIQuickBooksTwilio Google CalendarHubSpotStripe Shopify SlackXero SalesforceCal.com GmailSquare Google Sheets SupabaseOpenAI

The actual problem

Most local businesses don't have an AI problem.They have three systems that don't talk.

That is the layer the agent belongs in. Not a chatbot on the website. Software that does the job the copying-and-pasting person is doing right now, inside the tools you already pay for.

01You've tried the AI tools. None of them touch your systems.

ChatGPT wrote a nice email. It cannot see your calendar, your invoices or your customer list, so the person copying and pasting is still copying and pasting.

02The phone rings and nobody gets it.

A missed call at 6:40pm is a booked appointment somewhere else by 6:45. The voicemail gets checked in the morning, if it gets checked.

03Someone on payroll is the integration.

The scheduler doesn't know what the invoicing does. So a careful, expensive person spends Thursday copying numbers between two screens. They are the only reason the figures line up.

04A spreadsheet runs something critical.

Nobody wants to touch it. The person who built it may not work there anymore. It has no backup and no owner, and it decides who gets paid.

05You've been told your data has to go to the cloud.

It doesn't. A 27B model on a box in your back office does most of this work now, and nothing has to leave the building.

Three of the five and the build is worth a conversation. All five and it is worth one this week.

Anatomy of an agent

What's actually inside.Six layers, one audit trail.

Not a chatbot with a phone number. A trigger, a model held to a schema, memory in your database, scoped tools, guardrails that block before a write, and a person at the end of the line. Every layer writes to the same log.

  1. Audit log. Every call and every write, logged in your account. It is what the security note that ships with the build is written from.
AUDIT LOGHANDOFFHandoff06GUARDRAILSGuardrails05TOOLSTools04MEMORYMemory03MODELModel02TRIGGERTrigger01

Pricing

Two builds and a care plan.Prices on the page.

Fixed price, fixed scope, on paper before anything starts. What is in and what is out are both listed. You sign one page, not a statement of work with a change-order clause.

One thing, automated

Quick Win

$3,500 to $6,500

In production in ten business days

Pick the one thing that eats your week and we take it off your desk. One agent from the catalog, wired into the tools you run, tested against your real data.

Pick one

  • Missed-call text-back or AI phone answering
  • Intake that qualifies the lead and books it
  • Review requests and follow-ups on autopilot
  • Quotes from a photo or a voice note
  • Invoice chasing until paid or declined
  • A private AI box in your building, hardware included

Ships with. A written security note: what the AI can see and where that data lives.

When one specific thing is eating a person's week.

Talk it through

The system it all runs on

Business OS

$15,000 to $25,000

Three to six weeks, scoped in writing

Website, client database, and scheduling, ordering, repairs or invoicing, with the Quick Win agents wired through all of it. For companies whose current stack is a spreadsheet and three tools that disagree.

Everything in one place

  • Website and client database
  • Scheduling, ordering, repairs or invoicing
  • The agents from the catalog, wired in
  • Role-based dashboards for owner and staff
  • Every integration in one place
  • Cloud, offline, or both

Ships with. A written security audit against our 136-control methodology.

When the answer to 'where does that live' is four different places.

Book a fit call

With every build

Care

$600 to $1,500 a month

Starts on handover day

Agents break when a vendor changes an API. This is the plan that catches it before you notice, which is why it comes with every build rather than being optional.

Included

  • Hosting, monitoring and alerting
  • API and model drift watched
  • Security updates and verified backups
  • A fixed block of change hours
  • A monthly AI and security check

Ships with. Cancel with thirty days' notice. Your instance and data stay yours.

Required with every build. Priced by what is being watched.

Talk it through

Anything not on the catalog is quoted as a custom build with its own honest timeline. The offline box is Quick Win pricing with the hardware included and yours outright. Multi-location, multi-language and anything that takes payment over the phone are quoted separately.

How ten days actually works

Ten business days,and the clock is defined.

It starts when credentials are delivered and the spec is signed, not when you first email. That is the only honest way to promise a date. It is possible because proven components get assembled rather than invented. The ten-day clock applies to agents marked ready; a first build of Front Desk or Reconcile is scoped on its own timeline, in writing.

01
02
03
04
05
06
07
08
09
10
KickoffDay 0
BuildDays 1 to 7
Test on real dataDays 8 and 9
HandoverDay 10

Before the clock

Fit call

Thirty minutes. We establish whether this is worth building. You leave with the two things I would automate first, whether or not you hire me.

Before the clock

Scope, fixed

A written spec with a fixed price. In scope and out of scope are both listed. You sign one page.

Day 0

Kickoff

The clock starts when credentials are delivered and the spec is signed. Not before.

Days 1 to 7

Build

You see it running mid-week, not at the end. Nothing is a surprise on delivery day.

Days 8 and 9

Test on real data

Not a demo dataset. Your records, your edge cases, your worst-behaved customer.

Day 10

Handover

Documentation, the security note, and the keys. It runs in your accounts. You can revoke my access in one click.

Security posture

An agent with your keysis a new way in.

Almost nobody selling AI to local businesses will say that out loud. The real question about handing software the keys is not whether it works. It is what happens to you if it doesn't. That gets answered in the architecture, before it gets answered in a contract.

Your accounts, not ours

Your automation platform, your database, your model API key, your phone number. I build it, configure it, and hand you the keys.

We don't hold your data

Nothing is stored on our infrastructure. There is no copy of your customer list sitting somewhere waiting to be breached.

Revoke in one click

Access is delegated and reversible. The day you don't want me in there, you're not in a support ticket, you're in a settings page.

Every build ships with an audit

A written report on what the agent can reach, what it can change, and where that data lives. It is the document your insurer will eventually ask for.

A findings page from the sample audit report
Cover of the sample audit report

Sample report · 21 pages · redacted engagement · ungated

What we've built

No logos.The wiring itself.

Below is the Business OS reference architecture: intake and phone, money, repairs, operations, and the role-based dashboards behind all of it. It is drawn from a system running in production for a client, with the identifying detail removed; every node is a component we build from. Then the layers underneath: security, memory, and the guard that keeps agents inside their lane.

A jeweler's operating system

Client confidential

Website, client database, repairs, consignment and invoicing for a fine jeweler, replacing a spreadsheet and three tools that disagreed. In daily use by the owner and staff.

Security posture

Internal standard

A production application holding to twenty-seven of twenty-seven adversarial checks, and a 136-control audit methodology run against our own builds before anyone else's.

Agent memory

Infrastructure

Cross-model memory infrastructure and MCP servers: persistent context that survives between sessions and between vendors. The plumbing agents need to remember anything at all.

Agent fleet and guard

Internal

Six AI assistants on one shared memory store, sixty-three skills, and a pre-execution hook that hard-blocks dangerous tool calls before they run. The kill switch, built before it was needed.

Who builds it

An engineerwho has run the business.

Trained in

Software and security. Certified, and proven in production, not a bootcamp pivot.

Ran

A multi-location operating business. P&L, staff, corporate reporting.

Builds

The software the business runs on, and the audits that test it.

Based

Remote across the United States, on Eastern time.

Most people selling you AI have never run a business. Most people who have run one can't build. That combination is the whole offer.

I trained in software and security and then went and ran a business instead. Years of it: the P&L, a corporate parent to answer to, and the software nobody in the building liked.

Reconciling systems that disagreed. Watching a good person spend every Thursday moving numbers between two screens. Eventually I stopped complaining about it and built our own. Then people started asking me to build theirs.

That is why the first call is worth thirty minutes even if you never hire me. I will tell you what I would automate first, and I will tell you if the answer is nothing.

Questions

The things peopleask first.

We already have systems. Isn't that a problem?

It's the point. Agents that live outside your stack are chatbots. The value is in the plumbing: reading from the scheduler you already pay for, writing to the accounting system you already reconcile, booking into the calendar your staff already watch. If you had nothing, this would be a much smaller job and a much smaller return.

Can it run fully offline?

Yes. A Mac mini or a Ryzen AI Max box on your network runs an open-weight model in the 27B to 70B class, and the same agents run against it. Nothing leaves the building and it keeps working when the internet doesn't. From $6,500 installed with the hardware included and yours outright. Most companies end up hybrid: regulated work on the box, everything else on the frontier models.

Which AI models do you use?

Whichever is best for the job, on your keys. GPT, Claude, Grok and Gemini in the cloud, routed through a gateway you own with failover and spend caps; or Qwen, Llama and Gemma on a box in your building. The agents do not care which model is behind them, which is the point. When a better one ships, it gets swapped in under the care plan.

Ten business days. Really?

For a single agent on the catalog, yes, and the clock is defined: it starts when credentials are delivered and the spec is signed, not when you first email. It is possible because proven components get assembled rather than invented, which is also why anything not on the shelf gets quoted with its own honest timeline.

Who owns it when you're done?

You do. It runs in your accounts, on your keys, against your data, and the documentation is written for someone who is not me. You keep your instance and your data outright. We retain the right to reuse generic components and methods, which is standard and is what keeps the catalog moving.

Do you host our data?

No. Your automation platform, your database, your model API key, your phone number. Nothing is stored on our infrastructure, so there is no copy of your customer list sitting somewhere waiting to be breached. Access is delegated and you can revoke it in one click.

What happens when it breaks?

It will, eventually, because vendors change APIs and models change behaviour. That is why the care plan comes with every build rather than being optional. Monitoring catches the failure before you notice it, and a fixed block of change hours covers the fix. An unmonitored agent that silently stops working in month six is worse than no agent at all.

We're not technical. Is that a problem?

No. You need to know your business well enough to say what eats your week and who does it by hand. The technical detail is published on every listing for the people who want it, and safely ignored by everyone else.

Can you work alongside our existing IT provider?

Yes, and it usually goes well, because this is the work they typically do not have time for. Scope is written down before anything starts specifically so there is no ambiguity about who owns what.

Why is a security audit included in a build?

Because an agent with credentials to your systems is a new attack surface, and almost nobody selling them will tell you that. Every build ships with a written report covering what the agent can reach, what it can change, and where that data lives. It costs you nothing extra and it is the document your insurer or your biggest customer will eventually ask for.

Thursday and Friday afternoons · weekday evenings · ET

Book afit call.

Thirty minutes. I will have looked at how your operation runs before we talk, and you will leave with the two things I would automate first, whether or not you hire me.

  • Afternoons Thursday and Friday, evenings Monday to Friday
  • No deck, no discovery theatre
  • You get the two-item shortlist either way
Coverage
Remote across the United States

The form that books this call is Intake, from the catalog. The product is running on this page.

Confidential. A personal reply with open times, usually the same day.