# AiServa, by VYROX INTERNATIONAL SDN BHD > AiServa is a private AI workspace where an AI Agent does real work (plans steps, reads files and knowledge bases, searches the web, drives a browser, writes documents and drafts email) powered by AI you own: your own local AI server, and optionally your own cloud API keys. Sensitive work can stay entirely on your own server; a cloud provider is used only if your organisation adds its own key. Canonical URL: https://aiserva.com/ Full text: https://aiserva.com/llms-full.txt Last updated: 2026-10-01 Language: English (en-MY). Publisher: VYROX INTERNATIONAL SDN BHD, Malaysia. Get started: https://aiserva.com/app/signup.php (self-serve, free 14-day trial with every feature). Sign in: https://aiserva.com/app/login.php. Contact: WhatsApp https://wa.me/60196883338 (+60 19-688 3338). AiServa is a standalone product. It is not a CRM and not a hosted chatbot. AiServa itself supplies no models and no API keys, and does not charge per message or per token (your Usage page shows your own token counts and estimated cloud cost). It is unrelated to the xSERVA campus-operations family. ## How It Works AiServa is a multi-organisation platform: any organisation creates its own workspace and runs it itself. No custom build is needed. 1. Create a workspace at https://aiserva.com/app/signup.php (free for 14 days with every feature). 2. Connect your AI: pair hardware you already own with the one-line installer for macOS, Linux or Windows (single-use pairing code, valid 10 minutes), use an AiServa Basic, Pro, Max or Ultra server from VYROX, and/or add your own cloud API keys (34 providers). 3. Invite your staff and set roles, departments and permissions in the Client Console. 4. Work from any browser, the phone home-screen app, AiServa Desktop or the AiServa Chrome extension. ## Capabilities - AI Agent: completes tasks rather than just chatting. Streaming answers that survive a dropped connection, Agent Runs with retries and loop protection, a Backup Model, a Task Summary that writes itself (What AI Agent Did from AI Agent's own records, plus Done, Still Open and Next Steps), Web Browser panel for HTML files, and Commands (/name saved prompts). It reads a whole knowledge document when passages are not enough, batches independent lookups, and asks with one form instead of a string of questions. - Permission modes (in the message box, per task): Plan Only (looks things up and writes a plan; nothing changes until Run This Plan), Ask Every Time, Accept Edits (changes the person's own to-dos, calendar and scheduled tasks, asks before the browser or an MCP server) and Auto (with a Safety Check on actions the person did not clearly ask for). Questions offer Allow Once, Allow for This Task, Always Allow or Deny. Administrators add Rules (allow, ask or block a tool; an instruction for every task), monthly and per-task Spending Limits, and an Emergency Stop that pauses every action for everyone. - Sub-agents: the agent can hand one part of a task to a Researcher, Analyst, Reviewer or the organisation's own sub-agent, each with a fresh context and read-only tools; only its report comes back. - Ask for Details (Request Input): when details only the person can give are missing, the agent opens one form (choices, items with quantities and prices, dates, numbers, email addresses; up to 8 questions and 60 items) and the task waits up to 15 minutes for the answer. Used, for example, by a quotation skill: pick the customer, items and who to send it to, then get the quotation PDF and an email draft. - Draw on Image: circles, boxes, arrows, numbers, labels, highlights and blur on a copy of a photo in the task (up to 40 marks per drawing); the original never changes, and a model that reads images checks its marks and fixes them. People can also draw on an image themselves and save a copy. - Calculator: exact arithmetic, finance, dates and unit conversions, so figures never come from the model's head. - Calendar: Day, Week, Month, Agenda and Year views; repeating events with custom rules; outside guests invited by email with Yes, Maybe or No replies; calendars shared as Free/Busy, Details or Edit; working hours and Find a Time; import, a secret subscribe link, export to .ics, PDF, Excel or CSV, email a schedule, or save it to a knowledge base. - Scheduled Tasks: ask in plain words ("every Monday at 8:00 summarise last week's approvals") and AI Agent runs it as you in a new task, daily, on weekdays, weekly, monthly, once, or when an approval is decided, a to-do is done or a file is shared. Read-only until the person allows actions. - Console Apps: the apps people use beside their tasks (Task Summary, Knowledge Bases, To-Do List, Calendar, Scheduled Tasks, Approvals, Web Browser, Notifications) at organisation level in the Client Console, within the administrator's rights and record levels, plus Adoption Insights and Access Review. - Knowledge Bases: organisation, department or private. Answers cite their sources with [n]; each cited document shows its match percentage (cosine similarity) and opens the original: a PDF at the cited page, Word and Excel files with their layout in the browser, PowerPoint as text. Naming a knowledge base in a question searches only that one. Local embedding models or any OpenAI-compatible embedding API; vector store is built-in or Qdrant (only vectors and ids go to Qdrant, text stays on your server). Search: keyword (BM25) and vector search fused by reciprocal rank fusion, a similarity floor set for each embedding model, at most 3 passages per document, optional rerank, top 8 to the model. - RAG Lab: follow one question through every stage of retrieval: the question vector, the keyword and vector lists, fusion with what happened to each passage, the similarity floor, an AI rerank with 0 to 100 scores, the passages retrieved and the cited answer. A Chunks and Vectors view shows how each document was split and stored, with a cited summary. Same rights as AI Agent; Local Only knowledge bases never reach a cloud model; model steps are limited to 200 per person and 2,000 per organisation a day. - Outlook and Dropbox sources: a Local Only knowledge base can keep itself up to date, read-only, from an Outlook mailbox (Microsoft 365 or Outlook.com) or Dropbox folders. Sign-in, reading (PDF, Word, Excel, PowerPoint, email) and indexing run on the organisation's own AI server, where the sign-in is kept; AI Agent finds emails by sender, date and words, follows whole threads and links each answer to the original. - Internet Searcher: web search through Google, Brave or Tavily with your own key, Alibaba Cloud Search, or your own SearXNG, and reads the linked pages. - Link Reader: reads web pages and long PDFs. OCR Reader: reads scanned PDFs on your own server. - Browser Controller: runs on your AI server (browser-use and Playwright) or in your own Chrome through the AiServa Chrome extension. It never fills card or one-time-code fields and types a password only if you allow it and asks Allow or Skip before buy, pay, send, submit or delete. - Email: drafts appear as cards you send yourself, or the agent sends through your organisation's SMTP with generated files attached. - File Tools: creates PDF, Word, Excel (with formulas), PowerPoint, CSV, Markdown, TXT, JSON and HTML files. PDF Tools: merge, split and extract pages. - MCP Servers: connect outside systems over the Model Context Protocol, set to Ask Before Every Use or No Need to Ask; keys stay server-side. - Skills at personal, organisation and platform level, plus an admin-reviewed Skill Library of open SKILL.md skills (licence-checked, scanned for prompt injection, scripts never run). - Apps: the features you open beside a task (Task Summary, Web Browser, Knowledge Bases, To-Do Lists, Calendar, Scheduled Tasks, Approvals, Voice Dictation). Skills, Commands, MCP Servers and Plugins are separate add-ons; a Plugin bundles skills, commands and MCP servers, at Personal, Organisation or Platform scope. - Memory: shared layers for the platform, organisation, each department, each project and each agent, set by the people who manage them, plus private memory per person (200 memories) recalled by meaning with the organisation's own embedding model; secrets are refused; a fact or piece of work can be shared with a colleague for up to 90 days. - Private Mode (AI Agent Settings > Privacy): an organisation-wide lock that refuses every cloud AI route (cloud models, cloud web search, MCP servers, outside vector databases, browser speech), so all AI runs on the organisation's own servers with no fallback; plus a Read-Only Assistant switch that stops the agent sending email, using the browser or acting in other systems. - Signed server updates: AiServa's AI server software installs only updates signed with the release key, so a changed or unsigned update is refused. - Approvals (request and approve, time-limited grants, nobody approves their own request), File Sharing (view, download or edit permissions, expiry, full file history) and Notifications. - Frameworks: optionally run the agent on LangChain or LangGraph in a worker on your own server, with automatic fallback. - AiServa Desktop for macOS, Windows and Linux, with portal panels, system notifications and voice dictation (device-code sign-in, tasks sync with the web portal) and the AiServa Chrome extension (side panel, downloaded from the portal). - REST API v1 that runs AI Agent: POST /v1/tasks starts a task with a message (returns a run id at once, or waits up to 10 seconds with "wait"), POST /v1/tasks/{id}/messages continues it, GET /v1/runs/{id} returns status, answer, files made, usage and trace id, GET /v1/files/{id}/content downloads a file AI Agent made, POST /v1/tasks/{id}/stop stops it, GET /v1/models lists models. Also knowledge base search (GET /v1/knowledge-bases, POST /v1/knowledge-bases/search; Local Only knowledge bases are never searchable through the API), a memory API (list, search, add, change with If-Match, pin, history, delete), bug reports and feature requests, and usage. Each run happens as the key's creator with the organisation's models, tools, Rules, Emergency Stop, Private Mode and Spending Limits; nobody is there to approve, so anything that would ask is refused; tasks are read-only unless the key has Allow Actions; every run appears on Agent Runs. Keys: X-Api-Key header, scopes (tasks:read, tasks:write, knowledge:read, memories:read, memories:write, apps:read, usage:read, reports:read, reports:write), IP allow-list, expiry, Idempotency-Key; rate limits 120 a minute per key, 30 a minute for tasks, knowledge and memory, 3 running tasks per key. OpenAPI 3.1: https://aiserva.com/app/api/v1/index.php/openapi.json. Webhooks are HMAC-SHA256 signed (X-Aiserva-Signature t=,v1=), retried after 1 m, 5 m, 30 m, 2 h, 6 h and 12 h for up to 24 hours, turned off after 20 failures in a row, and carry ids and statuses only. - Admin oversight: What AI Agent Can Use shows, per person, which tools, MCP servers, knowledge bases, skills, commands, plugins and apps AI Agent will be offered and why something is not. Agent Runs shows where each run came from (User Portal, Client Portal, Scheduled Task, API, AiServa Desktop, Chrome Extension) with tool calls, questions, refusals, tokens and cost, never the words of a task. - Server management from the console: install, switch and stop models, restart services, view stats; the server backend updates itself. ## Models Local chat models: Qwen 3.x (default), Gemma 4, gpt-oss, Llama 3.1 and 3.2, DeepSeek-R1, Mistral Small, Ministral, Magistral, Phi-4, Granite 4, Nemotron. Local image models (Qwen-Image, FLUX, SD 3.5 and others) can be installed on the server. Cloud, with your own key: OpenAI, Anthropic, Google Gemini, xAI, Meta Llama API, Mistral, Cohere, DeepSeek, Alibaba Qwen, Moonshot Kimi, Z.ai GLM, MiniMax, StepFun, Xiaomi MiMo, Baidu ERNIE, Volcengine Doubao, Tencent Hunyuan, OpenRouter, DeepInfra, Together, Fireworks, Groq, Cerebras, NVIDIA NIM, SiliconFlow, or any OpenAI-compatible endpoint. Also works with vLLM, LM Studio, llama.cpp and LocalAI. ## Organisations and Security - Multi-organisation: a Client Console per organisation, a Client Portal for staff, and Platform Admin. - Roles, departments, per-user permissions, record levels (Own, Department, All) and per-tool rights. - TOTP two-step sign-in with recovery codes, per-organisation sign-in policy, 400-day stay-signed-in sessions with remote sign-out. - Branding (logo, sign-in backgrounds), audit log, secrets encrypted at rest, hashed API and pairing tokens, SSRF-guarded outbound requests, prompt-injection guards. ## Servers Chosen by use case, never by a specification sheet. Any server pairs with the same workspace, and more can be added later. - AiServa Basic: one person or a desk of two, a sole practitioner, a tutor or a home office. - AiServa Pro: a small team working with the AI Agent through the day, such as an accounting or law practice or a clinic. - AiServa Max: heavier document and knowledge-base work shared across a department. - AiServa Ultra: a whole building or multi-branch company with many staff signed in at once. Hardware you already own can be paired instead; the console shows which models fit it. ## Enterprise Company-wide use of the same platform: knowledge bases over company documents with cited answers (RAG), document processing, agent workflows with human sign-off, MCP servers for existing systems, tasks started by your own systems through the API, roles and audit. Deployment modes: connected, private network (LAN only) and air-gapped (updates on verified offline media). Adoption advice: start with one job people complain about every week. ## Key Pages - https://aiserva.com/ : home page - https://aiserva.com/product-tour/ : product tour, 40 real screenshots of AI Agent and the Client Console - https://aiserva.com/features/ : AI Agent tools (internet search, email, browser control, MCP servers, documents) and models (local or your own cloud keys) - https://aiserva.com/why-private-ai/ : your own AI server versus a cloud AI plan, costs, objections, when AiServa is the wrong answer, glossary - https://aiserva.com/enterprise/ : enterprise private AI: RAG, document processing, workflows, integration, infrastructure, access control and air-gap - https://aiserva.com/security/ : security and privacy: where a request goes, governance and audit, reliability when things fail - https://aiserva.com/use-cases/ : use cases by trade and role, a normal working day, and a fit check - https://aiserva.com/servers/ : AiServa Basic, Pro, Max and Ultra servers, setup paths, onboarding, maintenance and rollout - https://aiserva.com/ai-apps/ : AI Agent Capabilities and Apps - https://aiserva.com/ai-agent/ : how the AI Agent works: task loop, tools and limits, reliability, Smart Routing, frameworks, memory, to-do lists, calendar, voice dictation, sales documents - https://aiserva.com/skills-apps-connectors/ : skills, Skill Library, commands, plugins, MCP servers, Chrome extension with Ask mode, manual approval, schedules and recorded workflows - https://aiserva.com/desktop/ : AiServa Desktop for macOS, Windows and Linux, with portal panels, system notifications and voice dictation - https://aiserva.com/platform/ : administration, security, servers and models, What AI Agent Can Use, Agent Runs, a REST API that runs AI Agent tasks, and webhooks - https://aiserva.com/rag-knowledge-base/ : private RAG knowledge base, the AiServa Knowledge Engine and the RAG Lab - https://aiserva.com/workflow-automation/ : workflow automation with the AI Agent - https://aiserva.com/for/ : AiServa by profession - Profession pages: /for/accountants/, /for/architects/, /for/consultants/, /for/doctors/, /for/educators/, /for/engineers/, /for/hr/, /for/insurance/, /for/lawyers/, /for/logistics/, /for/procurement/, /for/property/ ## FAQ Q: What is AiServa? A: A private AI workspace where an AI Agent completes tasks using AI you own: your own local AI server and, optionally, your own cloud API keys. Q: Does my data leave my premises? A: Not if you use only your local server. Data goes to a cloud provider only when your organisation adds its own key and chooses that model. Q: Do I need special hardware? A: You need a local AI server (AiServa Basic, Pro, Max or Ultra from VYROX, or your own compatible machine), or your own cloud keys. Q: Is there a per-message charge? A: No. AiServa does not charge per message or token; it shows your own token counts and estimated cloud cost. Cloud providers bill you directly only if you use your own keys with them. Q: Can the agent act on websites? A: Yes, through the Browser Controller, which never fills cards or one-time codes and types a password only if you allow it and asks before buy, pay, send, submit or delete. Q: Can our own systems give AI Agent tasks? A: Yes. With an API key your systems start an AI Agent task through the REST API v1, collect the answer and the files it made, and can search knowledge bases. Each run follows the organisation's Rules, is read-only unless the key has Allow Actions, and appears on Agent Runs. Q: How do I start? A: Create a workspace at https://aiserva.com/app/signup.php. It is free for 14 days with every feature. For AiServa server hardware, WhatsApp +60 19-688 3338.