An AI assistant that runs on infrastructure you own — and proves it behaved, every day.
Juno runs on your server, with your keys. Your data stays on your own infrastructure and Anthropic account — it never passes through our servers. It refuses to overspend or do anything destructive without your approval — and hands you a plain-language receipt that proves what it did, refused, and spent.
Configuration & monitoring — not a guarantee.
You own the server, the keys, and the residual risk.
Your clients' data can't live in someone else's AI.
If you're under NDA, "just paste it into a chatbot" was never an option.
You handle confidential work — client files, contracts, code, private notes. The moment that data flows through a third-party SaaS, it's sitting on a vendor's servers, governed by a vendor's terms, somewhere you can't see and can't promise anything about.
So most people pick one of two bad answers: skip the AI entirely and do it by hand, or quietly route confidential data through tools their own agreements don't allow.
Juno is a third answer. The assistant runs on infrastructure you control, so your data stays on your own infrastructure and Anthropic account — it never passes through ours — and you get a daily record of exactly that.
Your box. Your keys. Hardened, then handed over.
We do the careful part — installation, hardening, and configuration — then leave you with something that's yours to keep and run.
We set it up on your machine
Your own server or VPS — infrastructure you control. We install the assistant, harden the environment, and configure it to the way you actually work. No shared tenancy, no mystery cloud.
Your keys, your data, your memory
It runs on your own Anthropic API key. Its memory lives in a plain file on your disk — one you can read, edit, back up, or delete. Nothing routes through us, and nothing is held hostage.
We configure the guardrails
Spend caps, password-gated destructive actions, and prompt-injection defenses — set up and enforced on your machine, not left to the model's good intentions. Controls you can inspect, not promises you have to trust.
You get a daily Safety Receipt
Every day, a plain-language record of what the assistant did, what it refused, and what it spent. Proof you can read in thirty seconds — and hand to your own clients if they ask.
What it can actually do.
Not a chatbot. An agent that acts — it monitors, drafts, and decides what to skip while you get on with your day.
Three things Juno does, quietly, every week.
Triages the inbox
Reads overnight mail on your box, drafts replies in your voice, and sets aside anything that needs a human. Nothing sends without you.
Reads the long documents
Summarises contracts, briefs and PDFs into the three points that matter — clauses, dates, risks — without a byte leaving your server.
Watches, and skips the noise
Keeps an eye on the folders, repos and feeds you care about, then hands you one digest a day — and the discipline to ignore the rest.
I work under NDA, so I'd quietly given up on using AI for the real work. Juno runs on my own box, on my own key — and the daily receipt is the thing I didn't know I needed. I can see what it did, what it refused, and that nothing left the server. It's the first setup I'd actually show a client.
Proof you can hand to your own clients.
Most "trust us" comes with nothing behind it. Juno's comes with a receipt. Every day it produces a plain-language artifact — no jargon, no dashboards to interpret — of exactly what the assistant did on your behalf.
- →It's readable. What it completed, what it refused and why, and what it spent against your cap — in thirty seconds.
- →It's evidence. Keep the receipts and you have a running, dated record of how confidential work was handled.
- →It travels. When a client asks how their data was treated, the receipt doubles as an NDA-compliance record you can actually show them.
- ✓Drafted 6 client replies
- ✓Summarised 3 contract PDFs
- ✓Updated memory file
- ✓+ 5 more, on your disk
- ⊘Delete /clients/* — gate locked
- ⊘Email external — off allowlist
- ⊘PDF instruction — read as data
Want a receipt like that for your work?
A few days of setup, then it's yours to keep — running on your box, proving itself every day.
What it will not do.
Three refusals, configured and enforced on your machine — so "behaving" isn't something the model is asked to remember.
Overspend
A hard daily budget. When the cap is reached, it stops and tells you — instead of quietly running up a bill on your Anthropic account. You set the number; it respects it.
Destroy without asking
Deleting files, sending external email, anything irreversible — gated behind a password only you hold. It asks for permission; it never assumes it. The default answer is no.
Be talked into it
Instructions hidden in a document, a web page, or an email are treated as data to read — not commands to follow. The contents of a file can't quietly become orders.
These are configured controls, enforced on your machine. They meaningfully reduce risk; they don't erase it. You own the box — and the residual risk — and the receipt exists so you can watch the controls do their job.
Priced like craftsmanship — not a subscription trap.
You pay for expert work, done once and kept. Everything optional is honestly optional.
A few days of expert work, done right. Installed, hardened, and configured to your workflow — yours to keep. No lock-in, no per-seat games. When we're done, it's your machine running your assistant.
Version-pinned updates and your daily Safety Receipt, with capped support — deliberately not 24/7. Cancel anytime; the assistant keeps running on its last pinned config. No hostage-taking.
You pay Anthropic directly, on your own account, at their price. We never mark it up and we never touch your keys. Your spend is yours to see, cap, and control.
The questions we'd rather answer straight.
Is it safe?
+
We don't claim that, and we'd rather not pretend. What we do is configure and enforce specific controls — spend caps, gated actions, injection defenses — and prove what they did each day. Those controls reduce risk; they don't make risk disappear. You own the residual risk. We'd rather be honest than impressive.
Is it guaranteed?
+
No. Juno is configuration and monitoring, not a guarantee. The Safety Receipt exists precisely so you can verify rather than take our word for it — proof beats promises, and it's the honest way to sell this.
What's the engine? Am I locked to it?
+
The engine today is Hermes, and it's interchangeable by design. The thing you're paying for is the configuration, the guardrails, and the daily proof — not any single model. If the engine changes underneath, your assistant and your controls don't.
Where does my data actually live?
+
On your server, in files you own. The assistant's memory is a plain file on your disk — readable, editable, yours to back up or delete. Nothing routes through us, and we don't hold a copy.
What does "capped support" mean?
+
A sensible monthly allowance for fixes, updates, and questions — not a 24/7 hotline, and we won't pretend it is. If round-the-clock coverage is what you need, we'll tell you plainly that we're not that, rather than sell you something we can't staff.
Can I leave?
+
Any time. It's installed on your box, running on your keys. Cancel monitoring and it keeps working on its last version-pinned config. There's nothing for us to switch off and nothing to take back.
Who is this actually for?
+
Technical solopreneurs, indie founders, and small agencies handling client data under NDA — people who can't responsibly pipe confidential work through a third-party SaaS, but still want a capable assistant. If you're comfortable owning a server, you're who we built this for.
Built carefully. Sold honestly.
If you handle data you can't hand to someone else's AI, let's set up one that stays on your box — and proves it, every day.
Founding rate (€200) open for the first few customers — honestly time-boxed.