Skip to content
Privatae Host

The personal firewallfor the agents you run.

An AI Host is the machine between you and the model providers. It runs the coding agents you already pay for, each one the vendor’s own binary, signed in the vendor’s standard way, under that vendor’s terms.

Memory from $9 a gigabyte a month, hosts free. Your agents run on your own subscriptions.

United States customers only, for now.

The Host desktop — the app rail, the circuit-trace wallpaper, and the Host's live status bar
The same Host on a phone
YOUR ACCOUNTSYOUR HOSTYOUR MACHINE
Your own accountsAny model, any agentIt learns what you keepNever billed for tokens

Five minutes

What is Privatae?

A network you own, with a machine on it that is yours. What the Host does, what the network around it lets your own machines do, how the Distributed Context Network moves context without moving your files, and what we are building it for.

The build pipeline

A build pipeline you design. Any model, any agent, every step.

Building on your Host starts as a conversation, becomes a plan, and runs as steps. You decide which coding agent and which model takes each step, in a protocol file you can edit. Change the protocol and the pipeline changes with it.

Your codebase is indexed on your own machine, so every coder starts from your own code. Your Host gives each coder only the context it should have, so it builds what the plan says and nothing else.

What you keep is logged. Pick a run, adopt a file, say what you liked or what you never want again, and the Host folds that into a preference profile that shapes the next round. Over time the pipeline builds the way you would.

Work arrives as a pull request on your own git server, with the agent holding only a short-lived token for that push, never your stored key. When the project is done, one click ships it as an app on your machine.

  • Any model, any agent, per step
    A protocol file names which engine and model take which step. Edit it and the pipeline changes.
  • Your codebase, indexed at home
    Search over your own code runs on your machine. The code and the vectors never leave it.
  • Controlled context
    The Host is the only thing that writes context to a coder. A coder gets the plan and its workspace, not the run of your machine.
  • It learns what you keep
    Picks, adopted files, and what you said in plain words become a preference profile. A "never use that" is enforced before a pod wakes.
  • Sealed keys, private git
    Credentials seal into your vault. An agent gets a short-lived token for the one push it makes. Code lives on a git server with no anonymous reads.
  • One-click ship
    A finished project ships as a signed app on your machine with one click. Merging is your click too; the Host never merges for you.

Bake-offs

Many versions at once, built off your own project.

For UI work, send one task to several agents at once. Each builds in its own pod against a copy of your own project, so what you see is what would ship.

The previews sit side by side. Pick the one you want, and adopt copies it into the project as it is, with no model in between and an undo if you change your mind. The pick is recorded, so the next round starts from what you chose.

  • Your own subscriptions
    Each agent signs in with the account or key you already pay for. Your rate limits, your spend, nothing marked up.
  • Judged by you
    You pick. A model never grades another model's work.
  • Adopted byte for byte
    The version you chose goes into the project exactly as built. Nothing is regenerated on the way in.
  • The pod goes, the work stays
    When a run ends its pod is destroyed. Its files, the branch and your pick survive.

The roster

The agents you already use, each in its own sandbox.

Each one is the vendor's own binary, signed in the vendor's standard way with the account or key you already have. It runs in a disposable pod on your machine's side of the line: its own user, its own workspace, only the credential it needs, and the same one way out every other agent uses. We comply with each provider's terms of service and never build a login of our own. If a provider's terms don't allow a use, we don't offer it.

  • Claude Agent SDK
    Anthropic
    Your own Anthropic account.
  • Codex
    OpenAI
    Your own OpenAI account.
  • Cursor
    Cursor
    Your Cursor API key.
  • Grok
    xAI
    Your own xAI account.
  • Kimi Code
    Moonshot AI
    Your Kimi or Moonshot key.
  • opencode
    Open source
    Your OpenRouter key — any model it lists.
  • VS Code
    Open-source build
    A full editor in your browser. Its workspace persists between sessions.

Names and marks belong to their owners. A tool on this list means your Host can run it in a sandbox on your machine — not that its maker endorses us.

The controller

One Host in charge of all of them.

Your Host is the controller. It keeps your accounts and your keys, and it gives each agent one task, a throwaway workspace holding the files for that task, and the sign-in for the one vendor that agent uses.

When the run ends the sandbox is released. The files it produced stay as that run’s output for a day, and the run you pick keeps its files for as long as you want it. An agent never sees your memory, your database, or the credentials for any other account.

The agents you talk to cannot run code at all. Code runs in a separate sandbox, and only there. Every run is on screen: status, output, cost. Every one of them ends the moment you say so.

How that is enforced
  • One task, one workspace
    An agent gets the files for its task and one vendor's sign-in. Not your memory, not your database, not another account's sign-in.
  • The vendor's own sign-in
    Each agent runs on your account with that one vendor, the way that vendor intends. It never sees the credentials for any other.
  • Code runs elsewhere
    Conversation and code are separate lanes. Code goes to a sandbox that is released when the run ends.
  • A kill switch on every run
    The live view shows every run. Any of them stops when you stop it.

The machine

A machine of your own, always on.

Every account gets its own machine: its own database, its own filesystem, its own hostname, its own identity. It keeps working when you close the tab. Open it from a laptop or a phone and it is the same machine, mid-task, where you left it.

  • A database you hold
    Your data lives in a database you hold on a machine that is yours. Cancel, and it is kept for 90 days in case you come back.
  • No inbound ports
    The machine dials out to one gateway. There is no port to scan, on it or on the machines you join to it.
  • Sleeps when idle
    An idle machine hibernates on its own and wakes on traffic. Sleeping costs nothing.
  • A desktop, if you want one
    A windowed desktop in any browser, phone included. The machine runs with or without it.

Egress

Every connection leaves through one proxy

A personal firewall is one place every outbound connection has to pass, where what leaves can be allowed or refused. A tool like Little Snitch is that place for the programs on your laptop. On your machine it is the proxy every agent connection leaves through, and for the browser your Host drives, the rules are yours to write.

Each agent on your machine has one route out of the platform: a proxy on the node it runs on, which refuses every address inside the platform, so nothing on your machine can reach another account’s.

For HTTPS that proxy is a tunnel. It passes the encrypted connection through and cannot read it. It writes down nothing about where anything went.

The browser your Host drives, and your Host’s vendor sign-ins, pass a second gate that you set rules on: allow a destination, deny one, or write no rule for it. With no rules the public internet is reachable, which is what a build step needs when it fetches a package.

When one of your rules denies something, the gate records that it refused a request. It does not record the destination. A list of every place your agents connect would show what you work on and who you deal with, so the platform does not keep one.

What we can see, and what we can't
  • One route out
    Unless you have pinned it to a machine of your own, every outbound connection from every agent goes through the proxy on its node. Platform-internal addresses are refused there.
  • Rules you write
    Allow a destination, deny one, or write no rule. Rules are signed when you approve them, and the gate on your machine checks that signature before it applies one.
  • No destination log
    A denied request gets a refusal. Where your traffic goes is not written down, on either side of the gate.
  • Your own address
    Pin a destination to a machine you own and your Host's and browser's traffic to it leaves from your connection, not this node's.

The network

Your hardware joins. Your Host reaches it.

One command installs the bastion on a Mac, Linux, or Windows machine: a single static binary with no kernel module, which installs without root if you want it to. From then on that machine and your Host share one private network. A GPU under your desk, a server in your office, a laptop on the road: your Host can use them, and nothing else can.

Your Host's internet traffic can leave through your own connection, under your own address. And managing the bastion is a fixed list of operations, never a free-form shell.

Episode 3 — The network you own
Read it, and watch the series
  • One command
    A static binary, userspace WireGuard, no kernel module. Installed in a minute, removable without a trace.
  • Scoped to your Host
    The tunnel reaches your Host and nothing else's. The key that opens it opens nothing else.
  • Your egress
    Outbound traffic can leave through your home connection. What your Host does on the internet uses your address, not ours.
  • An allowlist of operations
    The bastion answers a fixed set of operations with fixed arguments. Everything else is refused.

Models

Any model you pay for. Any model you run.

Your OpenRouter key and direct provider keys slot in. Models running on your own hardware join over your private network. A subscription you already pay for is used only where that provider's own tool allows it, signed in the vendor's standard way, inside the sandbox that runs it. We comply with each provider's terms of service, and we never build a login of our own.

Route each job to a different source if you like: chat, code, review, planning, research, embeddings. Per-model prices are shown in the product, so the choice is an informed one.

  • Your API keys
    OpenRouter plus direct providers. Keys seal into your vault. The model never receives them; your Host puts them on the request itself.
  • Your subscriptions
    Used only through the vendor's own tools and standard sign-in, under the vendor's terms. We are never in that billing path.
  • Your own hardware
    Models on your machines, reached over your private network. The request never crosses our side at all.
  • One lane per job
    Chat, code, review, plan, research, embeddings. Each gets its own source, changeable whenever.

Billing

Never billed for tokens.

The subscription buys the machine. Inference and embeddings are never billed, because they run on your keys, your subscriptions, and your endpoints, under each provider's own terms. There is no token meter in the code to mark up, and a tripwire that runs against production goes permanently red if a token charge ever lands.

The only meter is borrowed machine time. Extra machines your Host pulls on demand, such as build sandboxes and editor sessions, come with a set number of vCPU-hours in every plan. Past that they meter per second at $0.05 per vCPU-hour and go on your monthly bill. Your own machine never meters.

Pricing, in full
  • No token meter exists
    There is no token billing path in the code. A tripwire checks that continuously.
  • One monthly bill
    Nothing to top up and no balance to run dry. Usage past your plan is billed at renewal, and nothing else ever is.
  • Cancel and get the rest back
    Cancel and the unused time goes back to your card automatically, pro-rated to the cent.
  • Idle costs nothing
    A sleeping machine doesn't touch the bill.

The Host

Memory that outlives any one model.

Your Host is a named resident of your machine, not a session. Its memory persists across restarts, models, and providers, so you can swap the model underneath and it is still your Host. The model companies see the request you send. Your Host holds the rest.

Episode 1 — What a Host is
Read it, and watch the series
  • Memory that corrects itself
    Correct it once and the old version is retired, not deleted, with the lineage kept. Ask what it believed last Tuesday and it can tell you.
  • A memory can be hidden from a model
    Scope a memory away from a specific model or vendor. The scope is enforced when memory is fetched, not requested in a prompt.
  • Recall on your own hardware
    The embeddings behind recall can run on your own GPU over your own network. The text never leaves your hands.
  • A personality you can tune
    Ten weighted dimensions, set by sliders. It proposes changes; you approve them.

Community

Built with its members.

The platform is community-developed. What members ask for is what gets built — and the asking happens privately, from inside the product, never in a public issue tracker.

  • A place to learn
    A built-in, members-only community. People who run their own machine, comparing notes.
  • Members-only git
    git.privatae.ai hosts members' code with no anonymous reads. No scrapers, no training on your work.
  • Proposals that ship
    Feedback and feature proposals flow in privately from inside the product. The ones with traction get built.

Beyond one machine

Building a business on it? Want it on your own hardware?

Host is the machine. Ceigas is what you build a business on it with: sites, paywalls, and billing that settle to your own accounts, with your customers in your own tables. And the controller is licensed for hardware you bring, rented anywhere or owned, so a team can run it where its data already lives.

The personal firewall for the agents you run.

Get started

$9 a gigabyte a month, hosts free. Cancel any time and the unused time refunds automatically.

United States customers only, for now.

Privatae Host — Take control of your agents