Internal Proposal · Confidential

The brain behind
VitalRecordsOnline.

VRO Mind answers questions for every agent on your team — instantly, with sources, and without a single byte of customer data leaving your perimeter.

0M+
Customers VRO has served
0
Bytes leaving your network
0
Implementations. Hard-isolated.
0d
From start to proven
Why this works

Three commitments. Zero compromises.

VRO Mind is built on three principles that make it safe to run on real customer data the day compliance signs off — and useful to your team this month, regardless.

Local-first.

Every byte of data and every working part of the AI lives on hardware you own. The "cloud" in this system is your office.

Citation-grounded.

Every answer comes with its receipts. No fabrications dressed up as policy. If VRO Mind can't point at a source, it won't pretend to know.

Two builds. Hard-isolated.

The half that helps your team ships immediately. The half that touches customer data waits behind compliance — on its own server, with its own credential. Different risks, contained by design.

Live preview

Ask. Answer. Sources.

Pick a question. VRO Mind retrieves from its corpus and synthesizes a cited answer — every time.

vro mind · live
Which counties currently reject same-day rush requests?
What's the escalation path for a missing birth certificate?
Show me marketing spend and acquisition cost by channel last month.
VRO Mind · responding
Tap a question above to see VRO Mind in action.
One brain, two perimeters

Same intelligence. Two very different walls around it.

Both builds answer the same way and feel identical to the agents who use them. What changes is where the data lives, who can reach it, and what the audit trail looks like.

● Ships first

Knows VRO inside out — except who the customers are.

Built for agent enablement, training, ops, and ad-side intelligence. PII is stripped at ingest. No customer data ever lands here.

Build profile

Why two implementations and not "one with a flag."

A flag is a footgun. A separate database on a separate host with a separate token means that on the day someone asks "could a Non-Secure query ever return a customer name," the answer is no, by construction — not "no, if the flag is set right."

Same architecture. Different blast radius. A bit more setup, an entire category of incident gone forever.

One DB, "isolation flag" Code-level guard. Works until it doesn't. One bad query, one bad migration, one bad merge.
Two DBs, two hosts, two tokens Infra-level guard. Cross-contamination requires a deliberate, auditable act.
Same MCP surface, both sides Agent code doesn't change when Secure flips on. Zero migration friction.
How it works

Four layers. Every one of them yours.

Built on proven open-source foundations and runs on hardware you own. No vendor lock-in. No surprise invoices. No third party between your data and an answer.

01 · STORAGE

The library

An encrypted database holding every document, conversation, and reference VRO Mind has ever seen — searchable in milliseconds.

Encrypted at rest
02 · SEARCH

The librarian

Three search methods working together — meaning, keywords, and patterns — so the right answer surfaces no matter how the question is phrased.

Always cited
03 · INTELLIGENCE

The voice

A purpose-built language model on dedicated hardware. Wakes up when asked, sleeps when idle, never phones home.

Runs on-premise
04 · ACCESS

The doorway

Available to every agent through the tools they already use, on the same private network as the rest of VRO.

Internal network only
The plan

Useful in week four. Proven in two months.

Pacing is deliberate. We earn autonomy by demonstrating value as a responsive tool first.

Week 1

Scaffold both schemas

Two Postgres DBs on two hosts. One repo. Hard isolation enforced at infra level.

Weeks 2–4

Stand up Non-Secure

Ops, SOP, and ad corpus. Validate retrieval. Hand to early-adopter agents.

Weeks 2–4 ∥

Build Secure (synthetic data)

Same code, isolated infra. Audit log online. Synthetic corpus exercises every path.

Months 2–3

60-day soak

Real workflows. Measure hours saved + queue impact. Earn the keys.

When approved

Secure → live customer DB

Compliance sign-off in writing. Same MCP. Zero agent code changes.

First, it answers.
Then, it earns the right to act.

The same disciplined operations that have kept VRO running for over a million customers — now extended to the system that will help your team serve the next million.

A Foundation Operations proposal · Prepared for VitalRecordsOnline leadership