Self-hosted AI agents: what runs on your box, what can leave, hard token cap
Jaisiu is a self-hosted AI agent harness. The installer, the inference engine, the GitHub/YouTrack adapters, and the agent's working memory all run on your machine. The only thing that can leave your host is what you send to the Pryzm broker, and the broker has a hard token cap — agents pause when the cap is hit, your card is not charged. There is no analytics, no telemetry, and no model-training-on-your-data pipeline.
What runs on your machine
- The Jaisiu gateway (Node.js process), listening on
127.0.0.1:18789. - The local GGUF inference engine (the same engine Ollama uses — see docs/models).
- The GitHub adapter, when you wire it. Reads issues, opens PRs, writes review comments. Revocable from the SaaS side at any time.
- The YouTrack adapter, when you wire it. Reads tickets, comments, updates state. Revocable the same way.
- The agent's working memory: recent runs, past decisions, dispatch history — all under
~/.jaisiu/on your box.
What can leave (and how to audit it)
When a task routes to the broker (because it's too large or too hard for the local model), three things leave:
- The task description and any context the agent attached (the agent decides what to send).
- Tool output the agent chose to forward (code diffs, ticket contents, file excerpts — not the whole tool state).
- The model's response, which the broker returns and then discards after 30 days.
Every call is logged in the broker's audit trail. You can see exactly what was sent and when. The audit log itself never leaves the EU.
The hard token cap
The broker has a hard cap. When your token pool hits zero, agents pause — they don't fall back to a different model, they don't silently switch to BYO, and your card is not charged. The pool is part of your Jaisiu license: Basic is 200M / month, Fleet is 4B / month. Add-on packs (100M for $29, 400M for $69) extend the pool without a subscription change.
Get started
Install: pryzm.at/docs/install. One command, real installer script, no Docker required. Read the script before running it. Privacy and data-stays-local covers the rest.