Invite-only preview

Backend-as-a-service, built for what AI products need.

Pick one building block, or take all five. Every caller, human, agent, or script, gets exactly the access you define, walled off from everyone else.

Built from the search-and-security backend that runs a HIPAA product in production.

Context engineering

Give the model the right facts. Never something it shouldn’t see.

Applied AI comes down to getting the right information in front of a model call and keeping everything else out. You won’t out-train the frontier labs, they spend more on compute before breakfast than most companies ever raise, but you can out-context them: put the facts your product already holds in front of the model at exactly the right moment.

Web app
Mobile app
Agent
Script

every call, scoped

Access control checks who’s asking, and what they’re allowed to see

Exact lookup

One right answer: this order, this patient, this case.

Filtered search

Everything matching a condition: every incident this quarter.

Meaning-based search

When the right words aren’t the exact words.

None of that is safe to return to a caller who shouldn’t see it. A search result or an AI-generated answer that leaks one caller’s data into another’s isn’t an edge case, whether a person asked or an agent did on their behalf.

One model, everything derives from it

Declare your data model, and evolve it as you go.

The platform turns that one declaration into the back-end an AI product actually needs. The pieces stay in sync because they’re properties of the same model, not four systems you wire together and operate. Adding to that model later is a re-apply, not a rebuild.

one declaration

One declared data model

Typed records & documents
Hybrid search
Grounded RAG
MCP-native tools
Isolated automatically
Metered cost

Typed records

Define your own record schemas (fields, validation, references, sensitivity) and write records against them. Every write to an audited model is versioned, with optimistic concurrency.

Document ingestion

Ingest documents inline or by upload, organize them in folders, and retrieve their text and download URLs, indexed the moment they land.

Hybrid search, no separate vector DB

One search call spans records and documents, in keyword, semantic, or hybrid mode. Your source of truth is what’s searchable: no vector index bolted beside a database with a fragile sync job in between.

Grounded RAG out of the box

The same indexed content grounds inference: chat, retrieval over your own data, and document-scoped question answering, streamed, with citations back to the source.

Custom functions, same access rules

Write your own functions to control behavior: run them as an endpoint or a trigger on a data event, enforced by the exact same access rules as everything else.

MCP-native for agents

Twenty-three data-plane tools let an agent read and write your Vectros data directly over the Model Context Protocol.

Isolated automatically

Every caller’s data is walled off by default. A lookup can’t cross into someone else’s, and scoped keys carry exactly the permissions you grant, no more.

Cost tracks the work you do

Credit-based and pay-as-you-go: one credit is a penny, with a generous free read allowance on every plan. You pay to write, search, store, and run inference, and only for the capabilities you turn on. You don’t pay for other tenants’ scale.

Cost tracks the work you do: see the five-tier shape and the credit model.

No compliance cliff

Start lean. Scale to compliance-grade without re-platforming.

Every tier runs on the exact same per-caller isolation, from a weekend side project to a regulated workload. Turn on audit history or sensitive-field handling when you need them: the isolation underneath doesn’t change, and neither does the platform you’re running on.

Per-caller isolation, tamper-evident audit history, and sensitive-field handling ship today. See the full depth →

See the audit trail, don’t just read about it

The version timeline made visible: who changed what, when. Each row is append-only and part of a tamper-evident state-continuity chain, with sensitive fields already redacted in every historical row.

Audit Historyrecord rec_8f3a · intake_case
VerActorChange
v4svc.intake-botstatus: in_review → triaged
v3dr.okaforrisk_note: ••••••••• (redacted)
v2svc.intake-botpriority: normal → elevated
v1dr.okaforrecord created · 7 fields
Illustrative, synthetic data. Sensitive fields are destroyed before they reach retained history.

The single clearest answer to “why not a general-purpose back-end?” See what you can build or read why Vectros.

Getting going

Provision a real backend, and see what it built.

One command provisions it. From there, drive it however your product actually works: an agent over MCP, or the built-in UI.

1

Pick a blueprint, and provision it

One reviewable file declares the schemas, access, and a service principal. No application code required.

2

Drive it from an agent over MCP

Every capability on this page is also a native MCP tool your agent can call directly, with the same scoped-key enforcement as the API.

Read the MCP guide
3

Or drive it from the data-plane UI

The built-in app gives you a browsable UI over your typed model immediately: records, documents, folders, search. Fork it, or build your own with the React toolkit and SDKs.

terminal
vectros blueprint list
vectros bootstrap --blueprint agentic-sdlc

Three ready to run: Agentic-SDLC knowledge base · Second Brain · RAVV reference app. See them in action on the use cases page.

The backend for HIPAA-grade AI products

Evaluating for a regulated workload? Compliance specifics (HIPAA applicability, BAA coverage, attestation status) are available under NDA.

Where the boundaries are

What’s shipped, and what’s coming next.

Shipped

An agent reads and writes under the identical access policy as a human caller, over MCP.

Your own code runs server-side, under a grant you declare, on a data-write trigger or called directly.

Partner-facing surfaces are hardened through extensive adversarial security review.

In-perimeter inference is scoped to the data plane: sensitive content on that path stays inside the Vectros perimeter, not a whole-platform guarantee.

Roadmap

An agent, not code you wrote, operating inside that same governed boundary. We dogfood that internally on our own content and outreach operations first.

A SOC 2 report and a third-party penetration test.

Self-serve signup and a free tier, as we open access beyond the invite-only preview.

Full picture on the security page. Evaluating a regulated workload? Talk to us.