Fully Managed. Zero Infrastructure.

HelloDave.ai hosts and operates your Dave instance end-to-end: infrastructure, SSL, updates, and security hardening, all handled. You bring your AI keys; we handle the rest.

Join the Waitlist
Start here

How do you deploy Dave?

You don't. HelloDave.ai hosts and operates every Dave instance for you: infrastructure, SSL, updates, and an 18-step CIS/NIST security hardening pass are all handled as part of the managed service. You sign up, add your AI provider keys, and start building; most teams run their first workflow the same day.

How is a Dave server secured?

Every Dave instance runs behind an 18-step CIS/NIST-aligned hardening pass covering SSH, kernel, firewall, intrusion prevention, auto-patching, filesystem, and audit configuration, applied and maintained by HelloDave.ai. API keys and secrets sit in per-tenant vaults encrypted with AES-256 at rest, and each tenant's credentials are cryptographically inaccessible to any other tenant.

What's Included

Live the Same Day

Log in and start building. Most teams are running their first workflow within the same day.

SSL & Security Handled

Automatic SSL and domain configuration, plus 18-step security hardening, all managed for you.

Your Own Subdomain

A dedicated subdomain out of the box, fully isolated from every other tenant on the platform.

Bring Your Own AI Keys

Your credentials, your usage, your spend: we never proxy or mark up a single token.

Guide: Add a provider

Seat-Based Billing

Pay for the seats you have, on one graduated scale. No metering, no surprise overage.

Updates Handled

Platform updates ship automatically. Nothing for you to patch or maintain.

Full Tenant Isolation, Even in the Cloud

Managed doesn't mean shared. Every tenant gets its own isolated database access, encrypted secrets vault, and subdomain. HelloDave's own team has no access to your workflow data, prompts, or outputs.

That isolation is enforced by the database itself, not only by application code. Every tenant-owned table carries a PostgreSQL row-level security policy, so a query that arrives without your workspace context returns nothing at all rather than another tenant's rows.

API keys and secrets live in per-tenant vaults with AES-256 encryption at rest, so your credentials stay yours even though we operate the infrastructure.

Bring Your Own AI Keys

HelloDave never proxies your AI calls or pools credentials across customers.

When your workflow runs an agent, it calls your chosen AI provider using your API key, on your account.

That means your data isn't being used to train someone else's model. Your usage stays private.

You're never paying a markup on AI costs you can't see.

Supported providers
  • OpenAI
  • Anthropic
  • Google AI
  • Azure OpenAI
  • Ollama (self-hosted)
  • Any OpenAI-compatible endpoint
  • Any custom endpoint

Credentials and API clients, managed for you

One screen for AI providers, stored credentials, API clients and MCP registrations, scoped to your workspace alone.

The API Management screen on its MCP tab, listing one registration named Claude Code. It is marked active, carries the Full preset and thirty-four capabilities, and shows a key prefix, when it was last used and when it was created. Further tabs cover Providers, Credentials and API Clients.
API Management in a managed workspace. Keys are scoped to this workspace and never shared across tenants. Demo workspace with example data.
What a reviewer asks

Is HelloDave.ai SOC 2 certified?

Dave ships SOC 2 and GDPR compliance modes that a workspace administrator can switch on. They add read-access logging on sensitive resources and data-subject tracking, and SOC 2 mode recommends a seven-year audit retention window. Those are product capabilities that support your own compliance program. They are not an audit certification of HelloDave.ai, and we do not claim one.

Is my data backed up?

Yes, and not by you. Nightly database backups with off-site copies and automatic retention are part of how the platform is operated, alongside SSL, patching and the 18-step hardening pass. There is no backup job for you to configure and nothing for you to remember to run.

Can the HelloDave team read my workflow data?

The boundary that separates one workspace from another is the same one that stands between us and your content. The database connection Dave serves requests on holds no privilege to bypass its row-level security policies, and the service refuses to start if it is ever given one. Stored credentials, email passwords and webhook secrets are encrypted with AES-256-GCM, and their values are never returned over the API once saved.

Frequently asked questions

Do I need to manage a server to run Dave?

No. HelloDave.ai hosts and operates your Dave instance end to end: infrastructure, SSL, updates, and security hardening are all handled. There's no self-hosted option and nothing for you to provision.

How long does it take to get set up?

Most teams are running their first workflow the same day they sign up. There's no infrastructure to stand up and nothing to configure before you can start building.

Can I bring my own AI provider keys?

Yes. Your AI calls run under your own provider account and API key across 7 supported provider types. HelloDave never proxies or marks up your AI usage.

Is my tenant isolated from other customers?

Yes. Every tenant gets its own database access, encrypted secrets vault, and subdomain, and HelloDave's own team has no access to your workflow data, prompts, or outputs. Isolation is enforced in PostgreSQL by a row-level security policy on every tenant-owned table, so it holds even if application code ever forgets to filter.

Has Dave been through a security review?

Yes. The August 2026 platform release included a full pass against the OWASP Top 10 and the API Security Top 10 across every API route: eight findings, all fixed and re-verified against the running system, and dependencies were updated to clear every high-severity advisory.

Can a workflow be tricked into calling an internal address?

No. When a workflow step, a webhook, or a connected service calls a URL you supply, the destination is checked against private and internal address ranges before the request is made, and re-checked at every redirect, so a public address cannot bounce the request inward. Credentials attached for one host are dropped if a redirect crosses to another.

How is sign-in protected?

By a configurable password policy, account lockout after repeated failed attempts, and tight per-address rate limiting on sign-in, session refresh, and signup, with the counters held in a shared store so a restart does not reset them. reCAPTCHA or hCaptcha can be required at sign-in, and multi-factor authentication is available across eight built-in MFA provider types.

Ready to Build Your First Workflow?

No infrastructure to stand up, nothing to configure. Log in and start building today.

Deployment: Fully Managed AI Workflows | Dave