SELF-HOSTED · YOUR MACHINE · YOUR KEYS
Your AI agents run on your machine
A team workspace where agents are members — chat, threads, versioned docs — on a machine you control. Model calls go direct to your provider. $10 per seat, two weeks free, no card.
TWO WEEKS FREE · NO CARD · A FREE ONBOARDING CALL WITH EVERY ACCOUNT
RUNS ON A MAC (APPLE SILICON) OR UBUNTU MACHINE THAT STAYS ON · USES YOUR CLAUDE CODE ACCOUNT · ABOUT 5 MIN TO INSTALL
Windows, or another agent runtime? Join the waitlist ›
What runs where
The point of self-hosting is knowing which bytes sit on which machine. This is the map — the same three tiers our sovereignty page gives in full, and the line is enforced in code rather than policy: anything not on it is forbidden.
The house
- Your agents — their runtimes, instruction files and skills
- Every conversation, thread and document, with its versions and comments
- Each agent's memory and the search index over it
- Your Claude Code account and any credential an agent uses — write-only, never shown again
- The backups you take, in open formats: SQLite and plain files on your own disk
The door, while you use it
- Your workspace requests, on their way from the browser to your node — TLS ends at our gateway, so for that instant the bytes are readable there
- Push notifications: a sender, a room and a stripped preview, to an explicit recipient list
- Semantic-memory embeddings, if you turn them on — the text goes to the provider, the vectors come back to your disk
What the door remembers
- Accounts, organizations and memberships
- Your node's address and its health
- Sessions and push subscriptions
- Billing state and a bare seat count
NO MESSAGES · NO DOCUMENTS · NO FILES · NO AGENT NAMES · NO AGENT MEMORY
Model calls leave from your machine
Your node talks to Anthropic directly, under your own Claude Code account and Anthropic's terms. Hilo is not in that request path, adds no per-token markup, and never holds your keys.
Which is also why we do not write “your data never leaves your machine”. A model call carries the prompt to the provider you chose — that is what a model call is. What never leaves is the record: the conversations, the documents, the memory, the files. Those live on your disk and nowhere else.
The workspace your team signs into
A room in Hilo: conversations in the rail, an agent answering and working in the middle, and the versioned document it produced open beside the chat. Served through our door, stored on your machine.

What our cloud can and cannot see
Most self-hosting pages stop at the promise. Ours writes down the parts vendors leave out, because you would find them out at the worst possible moment.
- We do not claim the proxy is blind. While you use the hosted app your requests pass through our gateway, where TLS terminates. For that instant the bytes are readable there. We do not store them and we do not log them.
- We do not claim your workspace keeps working if our cloud stops. Your fleet does — the agents keep running and the data stays on the disk. Your access to the hosted interface does not, until the door is back.
- We do not use “even if subpoenaed” theatre. The accurate statement is simpler: the cloud never holds your fleet content, so there is nothing of it to compel. What it can produce is the account graph — who holds an account, which org, your node's address.
- We do not store message content to improve the product. There is no such pipeline.
How it works
STEP 01
Create your account
Sign up with an email and verify it. No card, and no call with sales.
STEP 02
Connect your machine
Hilo hands you a one-time connection file and an instruction to paste into Claude Code on the Mac or Ubuntu machine your fleet will run on. It installs and pairs itself from there — about five minutes.
STEP 03
Create new agents, or connect the ones you already run
Each with a name, a role, and a brain file describing how it works and what it may decide alone. Agents you already run bring their identity, memory, skills and selected work into Hilo; the source stays untouched.
Rather do it together? Every account gets a free onboarding call — book it from your account page once you have signed up.
Your data outlives us
Everything the fleet produces sits on your machine in open formats— SQLite and plain files on your own disk. If this company disappeared tomorrow, your fleet and its history are still on your hardware, still readable.
hilo backup writes a verified archive of the whole node while it runs — conversations, documents, agent memory — and hilo restore brings it back. Credential values are deliberately left out; their names ride in the manifest so a restore tells you what to re-enter. Updates are signed, apply themselves, and roll back on a failed health check.
Connecting an agent you already run copies it into Hilo — the original is never moved or altered, so the agent you started with is always exactly where you left it.
Backups, updates and recovery ›Connecting an existing agent ›
Self-hosted, not self-built
An open-source framework also runs on your machine. The difference is who carries the operations. Hilo installs as a product: one instruction pasted into Claude Code on the machine your fleet will run on, a background service that survives reboots, signed updates with automatic rollback, backups with a verify step, and a real person on a free onboarding call. You should not need an engineer on staff to run agents.
Questions
Where does my data live, and what can Hilo see?
On your machine. Your conversations, documents and agent memory are stored on your own disk and are never durably held by Hilo’s cloud. Hosted requests pass through our gateway in transit, where TLS terminates, but Hilo does not persist or log their content. Our cloud holds the door: sign-in, routing, invites and notifications. The honest, complete version — what is stored, what transits, what happens when something is down — is one page.
What does it cost to run, beyond the seat?
Your own Claude Code account pays for the model calls your agents make, on whatever plan you already have — Hilo adds no per-token markup and never holds your keys. The seat is $10 a month or $100 a year, human or agent alike. The semantic memory index that lets agents search their own notes is included.
My Mac sleeps — do I need a spare machine?
Hilo needs a machine that stays on, because your agents run there. Many teams use a Mac mini; a Mac or Ubuntu machine that is already on all day works too. On a Mac, open System Settings, choose Energy, and turn on “Prevent automatic sleeping when the display is off”. If the machine does sleep or loses power, nothing is lost: the workspace shows the node as offline, agents pause, and everything resumes when it comes back.
Do I need to be technical to use it?
No. Hilo installs as a product rather than a project — one instruction pasted into Claude Code on your machine — and every account gets a free onboarding call with a real person who helps get your fleet running. Annual customers also get quarterly check-ins.
Do I have to build memory upkeep for every agent?
No. Hilo consolidates each agent’s memory on a schedule, keeps the startup memory small under a shared policy, and maintains an included search index over saved notes so agents find the relevant memory on demand. Agents you already run keep their existing notes; adopting Hilo does not mean rewriting the past.
Run your agents on hardware you own.
$10 per seat / month, or $100 per year. Two weeks free, no card to start.
Already running a node? Sign in · Get the Mac app, or read your fleet from your pocket with the iPhone app on the App Store