How a Pillowcase system works.
You don't need to understand the stack to use your agent. But if you want to know what's actually running — here it is.
Three layers: your server, the runtime, the control plane.
What matters isn't the diagram — it's who can reach what. Each layer has one job, and the boundaries between them are the security model.
Your data lives in layer one. Our access stops at layer three.
The three layers
Layer 1 — Your server
A dedicated EU virtual machine. Nothing else runs on it. Inbound access is closed by default; there is no public management port.
More detail
Sized for a single-user agent with years of headroom for its data, and it exists exactly as long as your subscription does.
Layer 2 — The agent runtime
A pinned, tested build of the Hermes agent — never a moving "latest" tag. We test upgrades on our own instances first.
More detail
Every release is versioned, and rolling back to the previous version is a standard procedure, not an emergency.
Layer 3 — The Pillowcase control plane
Handles provisioning, billing, configuration, and health. It talks to your server, never the other way around — and only through a fixed list of permitted commands.
More detail
There is no management port open to the internet on your machine. The connection starts on your server and reaches out to us — if our control plane disappeared, your agent would keep running.
Memory and learning
Your agent remembers across sessions. Feed it documents, show it how you want things done, correct its mistakes — and it carries that forward. New information changes how it works next time.
Memory has limits. Over months, stored knowledge can drift from reality. The agent is excellent within a session and good across sessions, but benefits from occasional maintenance — just like any working document.
One customer per machine. Nothing shared.
Your agent runs alone on its server, and its memory and files stay on that machine.
EU servers
A dedicated virtual machine, hosted in the EU
One customer per machine
Never shared, no neighbours
Encrypted secrets
Your API key and bot token are encrypted before storage
Verified deletion
Cancel and the server is deleted — confirmed, not assumed
The stack (if you want the details)
For the technically interested — everyone else can skip this section.
Technical overview
- Agent framework
- Hermes (open source)
- Servers
- Dedicated EU virtual machines, one per customer
- Releases
- Pinned and versioned — upgrades tested on our own instances first
- Secrets
- Encrypted at rest; no reveal path exists, not even for support
- Management channel
- Outbound-only — your server connects to us, never the reverse
- Provisioning
- Automated setup and teardown, verified on completion
The architecture is half the story.
The other half is what it locks out. The security page lists the six controls this design makes possible.