- Passenger
- Your company
- Keys held by
- Your team
- AppYour server
- KeysYour database, your keys
- ConversationsYour server's memory
- ModelYour account or hardware
For teams whose policy decides where software runs. We install it in your cloud or data centre, and you hold every key.
The web app and the agent run in containers on a server you choose: your AWS, Azure or Google Cloud account, or hardware in your own data centre.
Every connection is stored in your database, encrypted with keys your team generates and holds. You set up the Slack, HubSpot and Google sign-in apps yourself, so each token is issued to your company.
Questions and answers stay in your server's memory, never in a database, and expire after a quiet spell. Each person's conversations are visible only to them.
Answers are written by a model you choose: one your company already has an account with, such as Amazon Bedrock in your own AWS, or one you run on your own hardware.
Hosted by us or installed by you, whereTF works the same way. Self-hosting changes where it runs, not how it treats your data.
Nothing is copied.
Each answer is searched live in your systems. There is no index, no crawl and no database of your company's content, in either setup.
Permissions follow the person.
Everyone connects their own accounts and sees only what those accounts could already open.
Credentials stay on the server.
The model reads questions and search results. It never receives a password or a token.
One call with your engineering and security leads: where it runs, which systems it connects to, and which model writes the answers.
We set it up with your team, in your environment: containers, database, HTTPS and nightly backups. Your administrators keep every password and key.
Your team registers the Slack, HubSpot and Google sign-in apps and an Atlassian token, then each person connects their own accounts.
We run your first real questions together, then hand over the runbook for accounts, updates and restores.
No. There is no usage reporting, no telemetry and no licence check. It talks only to the systems you connect and the model you choose.
Any model served through an OpenAI-compatible API: a provider account your company holds, such as Amazon Bedrock in your own AWS, or a model you host yourself. Answer quality depends on the model, so we test the one you pick with you before anyone relies on it.
One server with Docker, a PostgreSQL database (or the built-in SQLite for a small team) and an HTTPS address. Backups are a nightly export of that database, and restoring one is a single command.
Only the people your administrators create accounts for. There is no public sign-up page, and each person's connections and conversations are private to them.
Disconnect it in the app and its stored credential is deleted. To cut access entirely, also revoke it in Slack, Atlassian, HubSpot or Google's own settings, which only you control.
Tell us where it would run. A person replies, usually within a working day, to set up the scoping call.