# AiServa, Full Site Text for LLMs > AiServa is a private AI workspace where an AI Agent does real work (plans steps, reads files and knowledge bases, searches the web, drives a browser, writes documents and drafts email) powered by AI you own: your own local AI server, and optionally your own cloud API keys. Sensitive work can stay entirely on your own server; a cloud provider is used only if your organisation adds its own key. Canonical URL: https://aiserva.com/ Summary version: https://aiserva.com/llms.txt Last updated: 2026-10-01 Language: English (en-MY). Publisher: VYROX INTERNATIONAL SDN BHD, Malaysia. Get started: https://aiserva.com/app/signup.php (self-serve, free 14-day trial with every feature). Sign in: https://aiserva.com/app/login.php. Contact: WhatsApp https://wa.me/60196883338 (+60 19-688 3338). AiServa is a standalone product. It is not a CRM and not a hosted chatbot. AiServa itself supplies no models and no API keys, and does not charge per message or per token (your Usage page shows your own token counts and estimated cloud cost). It is unrelated to the xSERVA campus-operations family. ## How It Works AiServa is a multi-organisation platform: any organisation creates its own workspace and runs it itself. No custom build is needed. 1. Create a workspace at https://aiserva.com/app/signup.php (free for 14 days with every feature). 2. Connect your AI: pair hardware you already own with the one-line installer for macOS, Linux or Windows (single-use pairing code, valid 10 minutes), use an AiServa Basic, Pro, Max or Ultra server from VYROX, and/or add your own cloud API keys (34 providers). 3. Invite your staff and set roles, departments and permissions in the Client Console. 4. Work from any browser, the phone home-screen app, AiServa Desktop or the AiServa Chrome extension. ## Capabilities - AI Agent: completes tasks rather than just chatting. Streaming answers that survive a dropped connection, Agent Runs with retries and loop protection, a Backup Model, a Task Summary that writes itself (What AI Agent Did from AI Agent's own records, plus Done, Still Open and Next Steps), Web Browser panel for HTML files, and Commands (/name saved prompts). It reads a whole knowledge document when passages are not enough, batches independent lookups, and asks with one form instead of a string of questions. - Permission modes (in the message box, per task): Plan Only (looks things up and writes a plan; nothing changes until Run This Plan), Ask Every Time, Accept Edits (changes the person's own to-dos, calendar and scheduled tasks, asks before the browser or an MCP server) and Auto (with a Safety Check on actions the person did not clearly ask for). Questions offer Allow Once, Allow for This Task, Always Allow or Deny. Administrators add Rules (allow, ask or block a tool; an instruction for every task), monthly and per-task Spending Limits, and an Emergency Stop that pauses every action for everyone. - Sub-agents: the agent can hand one part of a task to a Researcher, Analyst, Reviewer or the organisation's own sub-agent, each with a fresh context and read-only tools; only its report comes back. - Ask for Details (Request Input): when details only the person can give are missing, the agent opens one form (choices, items with quantities and prices, dates, numbers, email addresses; up to 8 questions and 60 items) and the task waits up to 15 minutes for the answer. Used, for example, by a quotation skill: pick the customer, items and who to send it to, then get the quotation PDF and an email draft. - Draw on Image: circles, boxes, arrows, numbers, labels, highlights and blur on a copy of a photo in the task (up to 40 marks per drawing); the original never changes, and a model that reads images checks its marks and fixes them. People can also draw on an image themselves and save a copy. - Calculator: exact arithmetic, finance, dates and unit conversions, so figures never come from the model's head. - Calendar: Day, Week, Month, Agenda and Year views; repeating events with custom rules; outside guests invited by email with Yes, Maybe or No replies; calendars shared as Free/Busy, Details or Edit; working hours and Find a Time; import, a secret subscribe link, export to .ics, PDF, Excel or CSV, email a schedule, or save it to a knowledge base. - Scheduled Tasks: ask in plain words ("every Monday at 8:00 summarise last week's approvals") and AI Agent runs it as you in a new task, daily, on weekdays, weekly, monthly, once, or when an approval is decided, a to-do is done or a file is shared. Read-only until the person allows actions. - Console Apps: the apps people use beside their tasks (Task Summary, Knowledge Bases, To-Do List, Calendar, Scheduled Tasks, Approvals, Web Browser, Notifications) at organisation level in the Client Console, within the administrator's rights and record levels, plus Adoption Insights and Access Review. - Knowledge Bases: organisation, department or private. Answers cite their sources with [n]; each cited document shows its match percentage (cosine similarity) and opens the original: a PDF at the cited page, Word and Excel files with their layout in the browser, PowerPoint as text. Naming a knowledge base in a question searches only that one. Local embedding models or any OpenAI-compatible embedding API; vector store is built-in or Qdrant (only vectors and ids go to Qdrant, text stays on your server). Search: keyword (BM25) and vector search fused by reciprocal rank fusion, a similarity floor set for each embedding model, at most 3 passages per document, optional rerank, top 8 to the model. - RAG Lab: follow one question through every stage of retrieval: the question vector, the keyword and vector lists, fusion with what happened to each passage, the similarity floor, an AI rerank with 0 to 100 scores, the passages retrieved and the cited answer. A Chunks and Vectors view shows how each document was split and stored, with a cited summary. Same rights as AI Agent; Local Only knowledge bases never reach a cloud model; model steps are limited to 200 per person and 2,000 per organisation a day. - Outlook and Dropbox sources: a Local Only knowledge base can keep itself up to date, read-only, from an Outlook mailbox (Microsoft 365 or Outlook.com) or Dropbox folders. Sign-in, reading (PDF, Word, Excel, PowerPoint, email) and indexing run on the organisation's own AI server, where the sign-in is kept; AI Agent finds emails by sender, date and words, follows whole threads and links each answer to the original. - Internet Searcher: web search through Google, Brave or Tavily with your own key, Alibaba Cloud Search, or your own SearXNG, and reads the linked pages. - Link Reader: reads web pages and long PDFs. OCR Reader: reads scanned PDFs on your own server. - Browser Controller: runs on your AI server (browser-use and Playwright) or in your own Chrome through the AiServa Chrome extension. It never fills card or one-time-code fields and types a password only if you allow it and asks Allow or Skip before buy, pay, send, submit or delete. - Email: drafts appear as cards you send yourself, or the agent sends through your organisation's SMTP with generated files attached. - File Tools: creates PDF, Word, Excel (with formulas), PowerPoint, CSV, Markdown, TXT, JSON and HTML files. PDF Tools: merge, split and extract pages. - MCP Servers: connect outside systems over the Model Context Protocol, set to Ask Before Every Use or No Need to Ask; keys stay server-side. - Skills at personal, organisation and platform level, plus an admin-reviewed Skill Library of open SKILL.md skills (licence-checked, scanned for prompt injection, scripts never run). - Apps: the features you open beside a task (Task Summary, Web Browser, Knowledge Bases, To-Do Lists, Calendar, Scheduled Tasks, Approvals, Voice Dictation). Skills, Commands, MCP Servers and Plugins are separate add-ons; a Plugin bundles skills, commands and MCP servers, at Personal, Organisation or Platform scope. - Memory: shared layers for the platform, organisation, each department, each project and each agent, set by the people who manage them, plus private memory per person (200 memories) recalled by meaning with the organisation's own embedding model; secrets are refused; a fact or piece of work can be shared with a colleague for up to 90 days. - Private Mode (AI Agent Settings > Privacy): an organisation-wide lock that refuses every cloud AI route (cloud models, cloud web search, MCP servers, outside vector databases, browser speech), so all AI runs on the organisation's own servers with no fallback; plus a Read-Only Assistant switch that stops the agent sending email, using the browser or acting in other systems. - Signed server updates: AiServa's AI server software installs only updates signed with the release key, so a changed or unsigned update is refused. - Approvals (request and approve, time-limited grants, nobody approves their own request), File Sharing (view, download or edit permissions, expiry, full file history) and Notifications. - Frameworks: optionally run the agent on LangChain or LangGraph in a worker on your own server, with automatic fallback. - AiServa Desktop for macOS, Windows and Linux, with portal panels, system notifications and voice dictation (device-code sign-in, tasks sync with the web portal) and the AiServa Chrome extension (side panel, downloaded from the portal). - REST API v1 that runs AI Agent: POST /v1/tasks starts a task with a message (returns a run id at once, or waits up to 10 seconds with "wait"), POST /v1/tasks/{id}/messages continues it, GET /v1/runs/{id} returns status, answer, files made, usage and trace id, GET /v1/files/{id}/content downloads a file AI Agent made, POST /v1/tasks/{id}/stop stops it, GET /v1/models lists models. Also knowledge base search (GET /v1/knowledge-bases, POST /v1/knowledge-bases/search; Local Only knowledge bases are never searchable through the API), a memory API (list, search, add, change with If-Match, pin, history, delete), bug reports and feature requests, and usage. Each run happens as the key's creator with the organisation's models, tools, Rules, Emergency Stop, Private Mode and Spending Limits; nobody is there to approve, so anything that would ask is refused; tasks are read-only unless the key has Allow Actions; every run appears on Agent Runs. Keys: X-Api-Key header, scopes (tasks:read, tasks:write, knowledge:read, memories:read, memories:write, apps:read, usage:read, reports:read, reports:write), IP allow-list, expiry, Idempotency-Key; rate limits 120 a minute per key, 30 a minute for tasks, knowledge and memory, 3 running tasks per key. OpenAPI 3.1: https://aiserva.com/app/api/v1/index.php/openapi.json. Webhooks are HMAC-SHA256 signed (X-Aiserva-Signature t=,v1=), retried after 1 m, 5 m, 30 m, 2 h, 6 h and 12 h for up to 24 hours, turned off after 20 failures in a row, and carry ids and statuses only. - Admin oversight: What AI Agent Can Use shows, per person, which tools, MCP servers, knowledge bases, skills, commands, plugins and apps AI Agent will be offered and why something is not. Agent Runs shows where each run came from (User Portal, Client Portal, Scheduled Task, API, AiServa Desktop, Chrome Extension) with tool calls, questions, refusals, tokens and cost, never the words of a task. - Server management from the console: install, switch and stop models, restart services, view stats; the server backend updates itself. ## Models Local chat models: Qwen 3.x (default), Gemma 4, gpt-oss, Llama 3.1 and 3.2, DeepSeek-R1, Mistral Small, Ministral, Magistral, Phi-4, Granite 4, Nemotron. Local image models (Qwen-Image, FLUX, SD 3.5 and others) can be installed on the server. Cloud, with your own key: OpenAI, Anthropic, Google Gemini, xAI, Meta Llama API, Mistral, Cohere, DeepSeek, Alibaba Qwen, Moonshot Kimi, Z.ai GLM, MiniMax, StepFun, Xiaomi MiMo, Baidu ERNIE, Volcengine Doubao, Tencent Hunyuan, OpenRouter, DeepInfra, Together, Fireworks, Groq, Cerebras, NVIDIA NIM, SiliconFlow, or any OpenAI-compatible endpoint. Also works with vLLM, LM Studio, llama.cpp and LocalAI. ## Organisations and Security - Multi-organisation: a Client Console per organisation, a Client Portal for staff, and Platform Admin. - Roles, departments, per-user permissions, record levels (Own, Department, All) and per-tool rights. - TOTP two-step sign-in with recovery codes, per-organisation sign-in policy, 400-day stay-signed-in sessions with remote sign-out. - Branding (logo, sign-in backgrounds), audit log, secrets encrypted at rest, hashed API and pairing tokens, SSRF-guarded outbound requests, prompt-injection guards. ## Servers Chosen by use case, never by a specification sheet. Any server pairs with the same workspace, and more can be added later. - AiServa Basic: one person or a desk of two, a sole practitioner, a tutor or a home office. - AiServa Pro: a small team working with the AI Agent through the day, such as an accounting or law practice or a clinic. - AiServa Max: heavier document and knowledge-base work shared across a department. - AiServa Ultra: a whole building or multi-branch company with many staff signed in at once. Hardware you already own can be paired instead; the console shows which models fit it. ## Enterprise Company-wide use of the same platform: knowledge bases over company documents with cited answers (RAG), document processing, agent workflows with human sign-off, MCP servers for existing systems, tasks started by your own systems through the API, roles and audit. Deployment modes: connected, private network (LAN only) and air-gapped (updates on verified offline media). Adoption advice: start with one job people complain about every week. ## Key Pages - https://aiserva.com/ : home page - https://aiserva.com/product-tour/ : product tour, 40 real screenshots of AI Agent and the Client Console - https://aiserva.com/features/ : AI Agent tools (internet search, email, browser control, MCP servers, documents) and models (local or your own cloud keys) - https://aiserva.com/why-private-ai/ : your own AI server versus a cloud AI plan, costs, objections, when AiServa is the wrong answer, glossary - https://aiserva.com/enterprise/ : enterprise private AI: RAG, document processing, workflows, integration, infrastructure, access control and air-gap - https://aiserva.com/security/ : security and privacy: where a request goes, governance and audit, reliability when things fail - https://aiserva.com/use-cases/ : use cases by trade and role, a normal working day, and a fit check - https://aiserva.com/servers/ : AiServa Basic, Pro, Max and Ultra servers, setup paths, onboarding, maintenance and rollout - https://aiserva.com/ai-apps/ : AI Agent Capabilities and Apps - https://aiserva.com/ai-agent/ : how the AI Agent works: task loop, tools and limits, reliability, Smart Routing, frameworks, memory - https://aiserva.com/skills-apps-connectors/ : skills, Skill Library, commands, plugins, MCP servers, Chrome extension - https://aiserva.com/desktop/ : AiServa Desktop for macOS, Windows and Linux - https://aiserva.com/platform/ : administration, security, servers and models, What AI Agent Can Use, Agent Runs, a REST API that runs AI Agent tasks, and webhooks - https://aiserva.com/rag-knowledge-base/ : private RAG knowledge base, the AiServa Knowledge Engine and the RAG Lab - https://aiserva.com/workflow-automation/ : workflow automation with the AI Agent - https://aiserva.com/for/ : AiServa by profession - Profession pages: /for/accountants/, /for/architects/, /for/consultants/, /for/doctors/, /for/educators/, /for/engineers/, /for/hr/, /for/insurance/, /for/lawyers/, /for/logistics/, /for/procurement/, /for/property/ ## Where a Request Goes 1. A person signs in at aiserva.com (browser, AiServa Desktop or the Chrome extension) and gives the AI Agent a task. 2. The console sends the model work to the organisation's own paired AI server, or to a cloud provider only if the organisation added its own key and picked that model. 3. Files, knowledge-base text and original documents are stored on the organisation's own AI server. 4. The answer streams back. If the connection drops, the answer keeps running and resumes when the person reconnects; only Stop ends it. ## How an AI Model Runs on Hardware You Own An AI model is a large file of learned patterns. Answering a question means loading it into memory and running a great deal of arithmetic over it (inference), which is why a GPU or Apple silicon matters. Cloud providers meter inference because it costs them money on every request. When the model sits on your own server, there is no per-question cost from AiServa to pass on, and the document is read on your machine. ## Why a Task Agent, Not a Chat Box The AI Agent plans steps and calls tools in a loop: it can search a knowledge base, search the web, read a link or PDF, run OCR on a scan, operate a browser, create a spreadsheet or report, and draft an email with the file attached. Every run is recorded in Agent Runs, with retries, loop protection and a Backup Model if the main model fails. The Task Summary writes the summary itself and shows What AI Agent Did (steps, files, emails and questions, from AI Agent's own records) plus Done, Still Open and Next Steps, and collects the files a task produced so they can be saved to a knowledge base, zipped or emailed. ## Private Knowledge Bases (RAG) The AiServa Knowledge Engine, as built (details: https://aiserva.com/rag-knowledge-base/#aiserva-engine): - Storage: document text, chunks and vectors are stored on the organisation's own AI server. Access levels: Named People Only, Department or All Staff, with Allow or Deny per person or role; restricted documents are filtered again on every search. - Parse: PDF, DOCX, XLSX, PPTX, TXT, MD, CSV, TSV, JSON, HTML, XML and LOG. PDFs are read in the browser up to 5,000 pages; scanned pages are transcribed by the knowledge base's image-reading model. An optional OCR Reader runs on your server (25 MB per file). - Caps: 50 MB per original file, 8,000,000 characters per document, ZIP import of 25 files or 100 MB, 1,000 scanned pages per person per day. - Originals: kept on your server with a SHA-256 fingerprint; view, download or print. Word and Excel open with their layout in the browser (sheet tabs included), PowerPoint as text, and a cited PDF opens at the cited page. - Chunk: structure-aware passages of about 1,200 characters; tables kept whole or split between rows with the header repeated; no cuts mid-sentence; nearest heading stored; up to 500 characters of neighbouring text added at search time. - Embed: local models by default (qwen3-embedding 0.6B/4B/8B, embeddinggemma, nomic-embed-text, mxbai-embed-large, bge-m3, snowflake-arctic-embed2, granite-embedding). An organisation may use any OpenAI-compatible embedding API with its own key, never for knowledge bases marked Local Only. - Search: BM25 top 60 plus vector top 60, merged by Reciprocal Rank Fusion (k = 60), bonuses for exact identifiers, word coverage and headings, a similarity floor set for each embedding model (a keyword match gets 8 points of slack), at most 3 passages per document, optional language-model rerank, top 8 by default. Naming a knowledge base in the question searches only that one. Restricted documents a person may not read never take a place in the ranking. - Cite: passages are numbered [n] and only the sources the answer actually cites are kept, one chip per document with its match percentage (cosine similarity) that opens the original. - RAG Lab (https://aiserva.com/rag-knowledge-base/#rag-lab): the same search shown stage by stage: question vector, keyword list with BM25 scores, vector list with similarity, fusion with keyword rank, vector rank and what happened to each passage, the floor and what it dropped, an optional AI rerank with 0 to 100 scores, the passages retrieved with their neighbouring text and a grounded answer with [n] citations; plus a Chunks and Vectors view and cited document summaries. - Vector store: built-in, or Qdrant (only vectors and ids are sent, never text; one collection per vector size; falls back to the built-in store if Qdrant is unreachable). Local Only knowledge bases always use the built-in store. - Smart Routing adds a Knowledge Helper that searches for the Main Model with a relevance floor. ## How the AI Agent Works Details: https://aiserva.com/ai-agent/ - Task loop: the agent keeps a live checklist, calls one tool at a time with a plain-text tool call (so any model can use tools), reads the result and decides the next step, for up to 12 tool steps at the default Auto effort (6, 18 and 30 at Low, Medium and High), then answers with no tools. Each tool result is capped at 6,000 characters and labelled reference data, not instructions. An honesty rule forbids claiming an action unless a tool result shows it. - Tools and limits: Internet Searcher (Google, Brave or Tavily with your own key, Alibaba Cloud Search, or your own SearXNG; reads 1 to 3 linked pages), Link Reader (4,000, 8,000 or 16,000 characters), Browser Controller (3 to 40 steps, 2 browser runs per turn, 30 per hour), File Tools (PDF, Word, Excel with formulas, PowerPoint, CSV, Markdown, TXT, JSON, HTML; 5 files per answer, 100 per person per day, 20 MB per file), PDF Tools (merge, split, extract), Email (drafts you send, or SMTP send only to addresses typed in the task; 5 recipients, 30 emails per person per day), OCR Reader, Knowledge Search, and MCP servers (Ask Before Every Use asks the person first; scheduled tasks and API tasks use only those set to No Need to Ask). - Reliability: temporary errors (408, 409, 425, 429, 500, 502, 503, 504, 520 to 524, 529, network errors, timeouts) are retried twice, then a Backup Model answers. The Backup Model is never used when it is a cloud model behind a local Main Model on a turn with organisation data. One running turn per task, 16 to 38 model calls per turn depending on Effort, a 30-second heartbeat, and crashed turns are marked interrupted so Answer Again works. Only Stop ends an answer; a dropped connection does not. Cut-off answers continue automatically up to 5 times. - Control: permission modes per task (Plan Only, Ask Every Time, Accept Edits, Auto with a Safety Check), question cards with Allow Once, Allow for This Task, Always Allow or Deny, organisation Rules, monthly and per-task Spending Limits and an Emergency Stop. After Deny the agent never tries the same action another way. - Speed: the agent decides for itself whether to search the web or open the browser (no search runs before it starts), puts independent calls in one reply (also under LangGraph), reads a whole knowledge document when passages are not enough, and sees longer tool results on models with larger context windows. An answer that only announces what it will do is sent back once to do it. - Ask for Details: one form for details only the person can give (up to 8 questions, 60 items with quantities and prices); the task waits up to 15 minutes. Draw on Image: up to 40 marks per drawing on a copy of a task image, checked by a model that reads images. - Sub-agents: Researcher, Analyst, Reviewer and the organisation's own, each with read-only tools and a fresh context. - Smart Routing helpers: Vision Helper, Long Document Helper (40,000-character parts, up to 8), Knowledge Helper. - Frameworks (optional): LangChain or LangGraph in a Framework Worker on your own AI server, loopback only, hash-locked packages, tracing and telemetry forced off. LangGraph only decides the next step and never sees keys, model text, tool results or files. If the worker fails, the turn continues on AiServa. - Agent Runs: admins see where each run came from (User Portal, Client Portal, Scheduled Task, API, AiServa Desktop, Chrome Extension), status, tool calls, questions, refusals, retries, tokens and cost; the words of a task are never shown. - What AI Agent Can Use: for any person, the tools, MCP servers, knowledge bases, skills, commands, plugins and apps AI Agent will be offered, and why something is not. Each person sees their own list in Settings. - To-Do Lists and Calendar: side panels beside every task. The agent can add, complete, book and move items and checks them before answering questions about your day. Day, Week, Month, Agenda and Year views; repeating events with custom rules; colleagues and outside guests invited with Yes, Maybe or No replies; calendars shared as Free/Busy, Details or Edit; Find a Time; export to .ics, PDF, Excel or CSV, email a schedule or save it to a knowledge base. The calendar can be built-in, an MCP server such as Google Calendar, or both. Reminders go to the Notification Center and optionally email. Deleted items are kept 30 days. - Voice Dictation: off until an administrator switches it on. The Speech Reader runs on your own AI server (AiServa keeps no audio); the alternative is the browser's speech engine (Google in Chrome, Apple in Safari). It types a prompt; it does not transcribe recorded meetings. - Sales documents: quotation, sales order, invoice, purchase order, delivery order and credit note as PDFs on your letterhead, with server-calculated numbers and totals. - Task tidying and keyboard shortcuts: rename, pin, archive and delete tasks; Archived Tasks dialog; copy or edit a message you sent; Option or Alt plus Shift with R, P, A or Backspace. ## Skills, Commands, Plugins and MCP Servers Details: https://aiserva.com/skills-apps-connectors/ - Skills are SKILL.md files. The model sees only "name: description" and replies [USE SKILL: name]; the server holds that reply back, loads the full skill and the model answers again. The / picker lists skills and commands; a personal skill beats an organisation skill with the same name. Limits: name 48 characters; title 80, description 300, body 12,000 characters; 100 personal and 200 organisation skills. A drafted skill is saved only when the person presses Save Skill. - Skill Library: follows the agentskills.io format; Platform Admin imports only, from a GitHub or skills.sh address pinned to one commit or an uploaded SKILL.md or zip. Licence allow-list: MIT, Apache-2.0, BSD-2/3-Clause, ISC, 0BSD, Unlicense, CC0-1.0, CC-BY-4.0; GPL-family, MPL, EPL, SSPL, BUSL, non-commercial and similar licences are refused. An injection scan blocks hidden Unicode, instruction overrides, prompt-reveal requests, exfiltration wording, requests for secrets, long base64 blobs and identity changes, and warns on shell commands, script references and external links. Scripts and binaries are dropped and never run. New imports wait as Draft; updates wait as Pending review. - Commands: /name runs a saved prompt with $ARGUMENTS replaced by what follows. Layers: personal, then organisation, then platform. Built-ins: /summarize, /meeting-notes, /action-items, /email-reply, /translate, /explain. - Plugins and ready-made items: Skill, Command, MCP Server, Memory Pack and Plugin (personal, organisation or platform); a plugin holds skills, commands and MCP servers only. File format aiserva-app/1, up to 200 KB, never executed. Adding records exactly what it created; removing takes away only that; a failed add leaves nothing behind. Export never includes keys. Built-in plugins: Meeting Assistant, Writing Assistant, Developer Research. Built-in MCP servers: DeepWiki, Context7, Hugging Face, GitHub, Stripe. - MCP servers: Streamable HTTP over https only, protocol 2025-06-18, through the SSRF guard with no redirects; connect 8 s, handshake 20 s, tool call 120 s; up to 60 tools per MCP server and 30,000 characters per result; a Bearer key or custom header, sealed at rest and never sent to the browser. Approval modes: Ask Before Every Use or No Need to Ask. Ask Before Every Use: the agent asks the person each time, on the web and in AiServa Desktop; scheduled tasks never use those. Individual tools can be switched off. Scopes: personal, organisation, platform. - Chrome extension 2.1: Act or Ask mode, Automatically or Manually Approve, @ tab mentions, page pictures when the Main Model reads images, file upload (5 files, 10 MB each), Record a Workflow, hourly to monthly schedules, history across devices, server-enforced blocked sites. - Chrome extension "AiServa Browser Controller": Manifest V3 side panel, downloaded from the AiServa portal (not on the Chrome Web Store). Paired with an 8-character code valid 10 minutes, exchanged for a hashed token. Actions: navigate, open, switch and close tabs, go back, click, type, press key, select, scroll, wait. Limits: 30 steps per minute, stops after 6 identical steps. Refuses password, card and one-time-code fields; asks Allow or Skip before buy, pay, send, submit or delete. ## AiServa Desktop Details: https://aiserva.com/desktop/ - The AI Agent as a desktop app for macOS (Apple silicon and Intel), Windows and Linux, built on the open-source OpenCode project (MIT). - Sign-in with an 8-character device code valid 10 minutes, approved in the portal with password and two-step code. The app holds only a revocable device token (400 days, sliding), never provider, email or MCP server keys. - Uses the organisation's models through an OpenAI-compatible gateway, with the same retry and Backup Model. Receives the organisation's tools over MCP: internet search, page reader, knowledge search, file maker, document reader, PDF tools, Draw on Image (marks a copy of a photo or screenshot in the open folder), email, web browser, memory and the organisation's MCP servers. Missing details are asked with one form of questions to pick from. - Local tools work only inside the opened Workspace folder; the local app server listens on 127.0.0.1 only. Tasks sync both ways with the web portal and phone. - Simple Mode (default) and Developer Mode; admins choose which are allowed. - Portal panels (Summary, Knowledge Bases, To-Do Lists, Calendar, Approvals, Notifications) open in a side column through a one-time code, system notifications for reminders and approvals, and voice dictation through your own AI server (when the Speech Reader engine is chosen). - Installed from the portal (Profile > Download) with a one-line command that checks the SHA-256 fingerprint before installing. ## Admin, Security, Servers and API Details: https://aiserva.com/platform/ - Three places: the Client Portal where staff work (installs on a phone home screen), the Client Console where an organisation's administrators manage everything, and the Admin Console for VYROX Platform Admins. - Access: roles with 27 permission areas plus 9 tool-use rights (view, create, edit, delete where they apply), per-person Allow or Deny overrides, record levels Own, Department or All, a department tree with multiple membership, and per-person Tools They Can Use. - Sign-in: authenticator-app two-step sign-in (6-digit codes every 30 seconds) with 10 recovery codes; a Sign-In Policy can require two-step for everyone, set a minimum password length of 10 to 64 characters and limit new accounts to the organisation's email domains; stay signed in up to 400 days while in use, with a list of signed-in browsers and remote sign-out. - Branding and AI Identity: logo, accent colour and background on the organisation's own sign-in page; the assistant's name, introduction and whether it names the real model. - Approvals: requests for knowledge base access, app access, permissions or anything else; grants Until Revoked or for 1, 7, 30 or 90 days; nobody approves their own request; open requests expire after 14 days. - File Sharing: up to 25 people per share as Can View, Can Download or Can Edit, optional expiry, full per-file history. Notification Center collects every notice, with approvals waiting first. - Client Portal for administrators: the first icon in the Client Console opens an AI Agent that answers questions about the organisation, limited to what that administrator may see. - Console Apps: Task Summary (with Legal Hold), Knowledge Bases, To-Do List, Calendar, Scheduled Tasks, Approvals, Web Browser and Notifications at organisation level, within the administrator's rights and record levels, plus Adoption Insights and Access Review. - Servers and models: one-line installers for macOS, Linux and Windows; server tabs Overview, Models, Service and Settings; install, switch, stop and remove models with a hardware-fit check; self-updating server software; direct connection to vLLM, LM Studio, llama.cpp or LocalAI. Catalogue: 27 local chat models from 9 families, 9 local embedding models, 34 cloud providers plus any OpenAI-compatible endpoint. - REST API v1 (Client Console > Developers, with API Docs and an OpenAPI 3.1 file at https://aiserva.com/app/api/v1/index.php/openapi.json): POST /v1/tasks (start an AI Agent task; returns a run id at once, or waits up to 10 seconds with "wait"), POST /v1/tasks/{id}/messages (continue), GET /v1/runs/{id} (status, answer, files made, usage, trace id), GET /v1/files/{id}/content (download a file AI Agent made), POST /v1/tasks/{id}/stop, GET /v1/models; GET /v1/knowledge-bases and POST /v1/knowledge-bases/search (knowledge:read; Local Only knowledge bases are never searchable through the API); /v1/memories (list, search, add, change with If-Match, pin, history, delete); /v1/reports (bug reports and feature requests); GET /v1/usage (30 days), plus /v1/health, /v1/me and /v1/apps. - API runs: each run happens as the key's creator with the organisation's models, tools, Rules, Emergency Stop, Private Mode and Spending Limits. Nobody is there to approve, so anything that would ask is refused; tasks are read-only unless the key has Allow Actions; every run appears on Agent Runs. - API keys: shown once and stored hashed, sent in the X-Api-Key header, with scopes tasks:read, tasks:write, knowledge:read, memories:read, memories:write, apps:read, usage:read, reports:read and reports:write, an optional IP allow-list and expiry, and Idempotency-Key for safe retries. Rate limits: 120 a minute per key and 600 per organisation; 30 a minute per key for tasks, knowledge and memory; 3 running tasks per key. - Webhooks: https only, HMAC-SHA256 signed (X-Aiserva-Signature t=,v1=), retried after 1 m, 5 m, 30 m, 2 h, 6 h and 12 h for up to 24 hours, turned off after 20 failures in a row, with a Send Test button. Events: task.completed, task.failed, scheduled_task.completed, scheduled_task.failed, approval.requested, approval.decided, agent.emergency_stop, server.online, server.offline, user.created, user.updated, user.deactivated, app.binding.changed, subscription.ending, subscription.ended, report.updated. Deliveries carry ids and statuses only. ## Enterprise Private AI Company-wide private AI is built from the same features every AiServa workspace has, set up by the organisation's own administrators. VYROX optionally helps with larger rollouts, private-network or air-gapped deployments and custom MCP servers. ### What Company-Wide Teams Ask About - How private local AI works: where models run and how company data stays inside your own infrastructure. - Document Q&A and RAG: ask across company documents with a source on every answer. - Document processing: extraction, summarisation, review and preparation of business documents. - Workflow agents: multi-step, repetitive work handled by the AI Agent with Approvals and human sign-off. - Integration: ERP, HR, email, file shares and document repositories through MCP servers; your own systems start AI Agent tasks and search knowledge bases through the REST API, with signed webhooks. - Hardware and infrastructure: what a rollout needs and how it grows. - Access, security and audit: roles, record levels, audit log, and offline or air-gapped deployment. ### Four Layers on Your Side - Applications and agents: AI Agent with its tools, Knowledge Bases, Skills, Commands, Plugins, MCP Servers and workflow agents. - Language and vision models: open-weight models on your server. - Embedding model and vector store: built-in or Qdrant. - Access, audit and MCP servers: sign-in, roles, document permissions, the audit log, Agent Runs, and the MCP servers that link to your systems. ### Three Deployment Modes |Question |Connected |Private Network |Air-Gapped | |Where AI runs |Your server (plus your own cloud keys if you add them) |Your server |Your server | |Access from outside the office |Yes, through aiserva.com |Only over your own VPN |No | |Internet needed day to day |Yes |No |No, physically disconnected | |How updates arrive |Automatic |Scheduled window or offline media |Verified offline media only | |Suits |Most SMEs and multi-site teams |Regulated firms with a strict perimeter |Defence, R&D, highly sensitive IP | Private network and air-gapped modes are optional VYROX deployment services. ### Adoption - Everything opens from a normal web portal, desktop app or browser side panel, so rollout does not feel like an IT project. - Staff accounts, roles and departments are managed by your own admins from the Client Console. - Start with the one job somebody complains about every week. One removed weekly annoyance does more for adoption than launching everything at once. - Honest trade-off: there is a setup step before any of this starts, and if your team uses AI only occasionally, a monthly cloud plan can be cheaper. ## Workflow Automation The AI Agent turns repeated multi-step work into a task: read the inputs (files, knowledge bases, web pages, scans), do the work with tools, produce the output file, and route it for Approvals or draft the email for a person to send. Commands save prompts as /name shortcuts, Skills package know-how the agent follows, and MCP servers reach the systems you already run. ## Browser Controller Safety - Runs on your AI server (browser-use and Playwright) or in your own Chrome through the AiServa Chrome extension. - Never fills card, CVV or one-time-code fields. A sign-in password is typed by the Chrome extension or the server browser only if the organisation's setting allows it, and is masked everywhere. - Asks Allow or Skip before any buy, pay, send, submit or delete action. ## Skills, Plugins and Memory - Skills: personal, organisation and platform skills in SKILL.md format. The Skill Library holds admin-reviewed open skills with permissive licences, scanned for prompt injection; bundled scripts never run. - Apps: the features you open beside a task (Task Summary, Web Browser, Knowledge Bases, To-Do Lists, Calendar, Scheduled Tasks, Approvals, Voice Dictation). Skills, Commands, MCP Servers and Plugins are separate add-ons; a Plugin bundles skills, commands and MCP servers, at Personal, Organisation or Platform scope. - Memory: each person's saved memories and chat summaries are private to them, like ChatGPT or Claude memory, and secrets are refused. ## Security Detail - TOTP two-step sign-in with recovery codes and a per-organisation sign-in policy. - 400-day stay-signed-in sessions, with remote sign-out of other devices. - Secrets (API keys, SMTP passwords) encrypted at rest; API and pairing tokens stored hashed. - Pairing codes are single-use and expire after 10 minutes. - Outbound requests (link reading, web search, MCP servers) are SSRF-guarded. - Prompt-injection guards on web content, documents and skills. - Audit log of administrator changes (Platform Admin actions inside an organisation are tagged); File Sharing keeps full file history. - No model is trained on your data by AiServa. ## Profession Pages Each page explains what the AI Agent does for that profession using the capabilities above. - Accountants: https://aiserva.com/for/accountants/ - Architects: https://aiserva.com/for/architects/ - Consultants: https://aiserva.com/for/consultants/ - Doctors: https://aiserva.com/for/doctors/ - Educators: https://aiserva.com/for/educators/ - Engineers: https://aiserva.com/for/engineers/ - HR: https://aiserva.com/for/hr/ - Insurance: https://aiserva.com/for/insurance/ - Lawyers: https://aiserva.com/for/lawyers/ - Logistics: https://aiserva.com/for/logistics/ - Procurement: https://aiserva.com/for/procurement/ - Property: https://aiserva.com/for/property/ ## FAQ Q: What is AiServa? A: A private AI workspace where an AI Agent completes tasks (research, documents, spreadsheets, browsing, email drafts) using AI you own: your own local AI server and, optionally, your own cloud API keys. Q: Is AiServa a chatbot? A: No. The AI Agent plans steps and uses tools to finish tasks, and produces real files such as PDF, Word, Excel and PowerPoint. Q: Does my data leave my premises? A: Not if you use only your local server. Data is sent to a cloud provider only when your organisation adds its own key and selects that model. Q: Does AiServa provide the AI models or API keys? A: No. Models run on your own server, or you bring your own cloud keys from 34 providers. Q: What hardware do I need? A: None, if you use your own cloud API keys. For local AI: a machine you already own, paired with the one-line installer on macOS, Linux or Windows, or an AiServa Basic, Pro, Max or Ultra server from VYROX. Q: Which models can I run? A: Locally Qwen 3.x (default), Gemma 4, gpt-oss, Llama, DeepSeek-R1, Mistral family, Phi-4, Granite 4, Nemotron and others; in the cloud any supported provider or OpenAI-compatible endpoint with your own key. Q: Is there a per-message or per-token charge? A: Not from AiServa. If you use your own cloud keys, that provider bills you directly. Q: Can it work fully offline? A: Yes, as an optional private-network or air-gapped deployment service from VYROX. Q: Can the agent use company systems? A: Yes, through MCP servers you add, which let the agent use your systems' tools, and knowledge bases built from your documents. Your own systems can also start AI Agent tasks and search knowledge bases through the REST API v1, and receive signed webhooks. Q: Can our own systems give AI Agent tasks? A: Yes. With an API key your systems start an AI Agent task through the REST API v1, collect the answer and the files it made, and can search knowledge bases. Each run follows the organisation's Rules, is read-only unless the key has Allow Actions, and appears on Agent Runs. Q: Who approves sensitive actions? A: Approvals routes requests to the right person with time-limited grants, and nobody can approve their own request. The Browser Controller asks before buy, pay, send, submit or delete. Q: Is there a desktop app? A: Yes. AiServa Desktop runs on macOS, Windows and Linux with device-code sign-in, and tasks sync with the web portal. The AiServa Chrome extension is downloaded from the portal. Q: How much does it cost? A: Every workspace starts with a 14-day free trial with every feature. AiServa does not bill per message or per token; cloud providers bill you directly for your own keys, and local AI costs the hardware you choose. ## Contact VYROX INTERNATIONAL SDN BHD, Malaysia. Sign up: https://aiserva.com/app/signup.php. WhatsApp: +60 19-688 3338 (https://wa.me/60196883338).