Why you can trust it
Trust you can hand to your boss.
Your context is yours — private by default, portable across every model, and every change on the record.
Runs inside AWS
Everything on the record
Never trains public models
Customer PII · onboarding
VAULT
Locked away, kept separate, and left out of every share — no exceptions.
AUDIT_LOG · append-onlylive
Approval A person signs off
An assistant wants to export 1 record for an outside review. Nothing leaves until you say yes.
Who we are
A small team building AI you can actually trust
Charlie Hutchinson
Engineer
Luke Fitzgerald
Engineer
Thomas Grisamore
Engineer
0
of your data trains public models
0%
of changes on the record
0
things shared without a person approving
Carve Protect
Simple promises you can count on.
Private by default
- Stays in your workspace — no one else can see it
- Never used to train public models
- Locked down at all times
A person approves what's shared
- Nothing is shared until a person approves it
- A locked vault for secrets — never shared
- Nothing is ever deleted — only set aside
Everything on the record
- Every read, change, and approval is logged — with who and when
- Big actions pause for a person to sign off
- Append-only by design — nothing in the app ever edits or deletes a record
Safety at the model layer
New models, without the blind leap.
Being model-agnostic can't mean trusting a new model blind. The guardrails live in our layer — not in any model.
Inference stays inside AWS
- Models run on AWS Bedrock — your company's data never leaves the AWS boundary
- Your data is never used to train public models
You control the model pool
- Models are added deliberately, never auto-adopted — you decide which are allowed
- Set the pool by policy, per agent or company-wide
Every choice on the record
- Which model ran each task is written to the append-only audit log
- Switching models never changes what your company knows
On the record
See exactly what happened, every time.
Every read, change, and approval is written down — and nothing can be edited away after the fact.
audit_events · tenant=acme-fs · append-onlylive
10:14:02ARCHIVAL_SEARCH#9241
10:14:03BLOCK_READ#9242
10:14:07BLOCK_UPDATED#9243
10:14:12HUMAN_APPROVAL#9244
10:14:18SESSION_WRITEBACK#9245
10:14:21BLOCK_SHARED#9246
Illustrative stream — sample audit events.
Questions we get asked
Plain answers, no hedging
- TrainingDo you use our data to train AI?
- Never for public models. Inference runs on AWS Bedrock, which doesn't train on your data. Down the road, your data may fine-tune a model that's private to your company — on your data, for you. It's never used to train anyone else's model.
- Your dataIs our memory really ours?
- Yes — it stays in your workspace, and nothing is shared until a person approves it.
- Joiners & leaversWhat happens when people come and go?
- A new hire's assistant can pick up a colleague's know-how — with that colleague's sign-off — so nothing walks out the door.
- ModelsWhich AI models do you use?
- As many as fit the job — CarveAI routes across 30+ frontier and open-source models, and you set which are allowed by policy. New models are sandboxed before they ever touch production, and switching never loses your context.
Book a demo
A model layer you can actually trust.
A 30-minute walkthrough — see it for yourself.