For builders
Stop assembling a back-end. Ship the product.
The vector DB, the search layer, the auth, the isolation, the RAG: that’s the six-month nightmare hiding behind the weekend demo. Vectros is the one back-end you don’t build, and don’t operate.
Store it, search it, ground a model on it, walled off from everyone else, in minutes.
Self-serve and a free tier are on the way as we open access. Right now it’s invite-only. Request access and we’ll get you in.
The plumbing you were about to write
You wanted to ship a thing people use. Instead you’re three weekends into wiring:
- a database, then a separate vector index beside it
- the embedding job that keeps the two in sync, and the cron that re-runs it
- auth and scoped keys, hand-rolled
- per-tenant isolation: a WHERE owner_id = ? on every query, and the cold sweat that you forgot one
- a RAG pipeline stitched out of four libraries
- and then you own and operate all of it, forever, while the actual product waits.
The back-end is the easy demo and the long nightmare. You don’t have to build it. You don’t even have to run it.
What you actually get on day one
Concrete things you can run, not adjectives.
One model, not four systems
Define your record schemas (fields, validation, references, what’s searchable) and write records against them. Ingest documents inline or by upload, drop them in folders, retrieve text and download URLs. Every write to an audited type is versioned, with optimistic concurrency so two writers don’t silently clobber each other. Search spans records and documents in one call: keyword, semantic, or hybrid.
Grounded RAG, out of the box
Ask a question over your own data and get an answer with citations back to the source, streamed. Ask against a single document, or across the whole indexed corpus. It ships as the product, not as a retrieval framework you assemble and then maintain forever. In-perimeter inference is the default path: on the data plane, sensitive content stays inside the Vectros perimeter instead of crossing to a third-party model host.
Agent memory that’s safe to point at customers’ data
One line in your agent config, and it searches the corpus, reads and writes records, ingests documents, and asks grounded questions. No custom integration code, no web-fetch surface. The same enforcement that isolates your human callers isolates the agent too. See the full tool list.
Isolated automatically, no forgotten WHERE clause
Every data-plane resource is partitioned by an auth-derived context: a lookup that can’t prove it belongs there returns nothing, not everything. Lookups can’t cross a context boundary, search can’t return another tenant’s content no matter what filter the query carries, and a probe with someone else’s id gets the same “not found” as a probe with an invented one. This isn’t row-level rules you hand-author and pray you got right on every query. It’s a structural property of the platform, the same on every tier.
Pay for what you turn on
No surprise invoice. No idle burn. No enterprise pricing to start. The cost story here is architecture, not a discount:
- Turn a capability on, and you pay for it. Leave it off, and it costs nothing. Turn off embedding on a record type and there’s no vector cost on that type at all. No index sitting there billing you to do nothing.
- Each tenant’s index is isolated, so you don’t pay for other tenants’ scale. Your cost tracks your work, not the size of the platform.
- Cost follows the work you do, not a flat floor you pay for the privilege of starting.
Pricing isn’t buried in marketing copy where it goes stale. See the pricing page for the tier shape and credit model.
The part you don’t throw away later
Start lean. Scale to compliance-grade without re-platforming.
The trap every cheap tool sets
It’s great until you land the customer who needs isolation, audit, or a BAA. And then the price leaps to an “enterprise” tier, or the auth/DB you picked was never eligible for that customer in the first place, so you rip it out and re-platform mid-flight, usually with that first real customer watching.
Why there’s no wall here
Isolation is on from day one for every tenant. When a customer needs audit history, you turn it on. Every write to an audited type already accrues a tamper-evident version record. When a customer needs sensitive-field handling, you turn that on too: values destroyed before they ever hit history, masked on read unless a token is scoped to reveal them, and kept out of the search index entirely. Same platform, no rewrite, no escape tax.
The platform was extracted from a HIPAA-grade clinical product and hardened through extensive adversarial security review. The compliance story isn’t the pitch here. It’s the proof the ceiling is gone.
Common questions
The things you’re already thinking
Two ways to prove it this week
Bootstrap a blueprint, or fork a full app.
A blueprint provisions in one command and drives from an agent or the data-plane UI. A reference app is a full front end with its own sign-in, forked and deployed on your own host.
Second Brain
Dump every note, idea, and link in one place. Then just ask it.
A personal knowledge base: capture notes, ideas, and links as typed records, then ask them anything with grounded, cited answers. The widest on-ramp: semantic recall plus structured facts, no app to write.
vectros bootstrap --blueprint second-brainRAVV reference app
full app, not a blueprint runA production-grade app with its own sign-in and zero backend of your own.
Fork the RAVV reference app, point it at your own identity provider and host, and apply its blueprint the same way you would any other: vectros bootstrap --blueprint takes a file path you own, not just a bundled name.
Where it’s limited
What’s scoped, or not built yet.
Bootstrapping needs a human step.
Applying a blueprint requires a bridge token from the developer portal. There’s a real sign-in; there’s no fully unattended path that mints one for you.
The agent surface has no web tools, on purpose.
No web-search, no scraping, no third-party fetch. The MCP server reaches your Vectros data plane and nothing else.
Agent document upload is local-file on the desktop transport.
Over HTTP, ingest text inline (or call the SDK from your own code).
Audit history is tamper-evident, not tamper-proof.
The SHA-256 state-continuity chain makes out-of-band alteration detectable; the platform doesn’t re-verify the chain for you on every read.
It’s an invite-only 0.x preview.
Some things are reserved and named as such in the docs. We draw the line ourselves rather than round up.
Ready to stop plumbing?
Invite-only today. Self-serve and a free tier are on the way as we open access.