What's Under the Hood
How your Sarudo instance is put together — what runs on your own server, which outside services it calls, and why every one of those bills to an account in your name.
What Runs Where
Your Sarudo instance runs on your own private server, with your own database, your own file storage, and your own configuration. On that server we run your Sarudo employee itself, a secure tool layer that powers the capabilities documented throughout this site, a private database with semantic search, web search that runs from your own instance, built-in browser automation, and a secure gateway. All of it is yours — the server sits on your provider account, nothing is shared with other Sarudo clients, no database multi-tenancy, no cross-customer data flow. If we stood up a hundred Sarudo instances tomorrow, they would be a hundred independent servers with a hundred independent databases, each one billed to its own owner.
The "dedicated infrastructure" promise in the Security & Privacy article is not marketing — every one of the services above runs exclusively for you, on your server, with your data.
The AI Model Stack
Your AI employee is powered by a stack of language models — a primary model for reasoning and writing, and a fallback that takes over if the primary hits an issue. Setup wires that stack up and picks the models, because the right model for a given role changes every few months as the providers update, and choosing well is part of what the hours pay for rather than a setting you should have to manage. The API keys live in provider accounts registered to you: usage bills from the provider straight to you, at the provider's own rates. Sarudo does not resell model access, does not fold it into a fee, and does not add a margin. If you want to know what a month cost, you read it off your own provider dashboard.
You pay for model usage directly, at cost. Setup creates the provider accounts with you and tells you what each one charges; from then on the bill goes to you and you can see every line of it. Changing the model line-up later is support work, not a plan change.
Supporting Services Wired Up for You
Beyond the model stack, a handful of supporting services get wired up during setup so they work from day one. Image and GIF search supplies hero photos and reaction GIFs for blog drafts and social posts. A cloud browsing tier reaches bot-hostile sites (LinkedIn, X, Facebook and Instagram outside Publer, Glassdoor) that a normal browser cannot. Publer covers social posting across nine networks. Web search runs from your own server, so it carries no third-party search bill at all. SEO research runs against a keyword-data provider. Every one of these except web search runs on an account in your name — setup creates them with you, tells you what each one charges, and the invoices go to you at cost.
What You Still Connect
A second group has to be yours for a reason beyond cost — the outside world sees these as you. Your Twilio account (the phone number is yours; per-minute charges bill to it). Your Stripe account (payouts land in your balance, never in ours). Your email account (the from-address on sent mail is yours, and deliverability follows your domain's reputation). Your Notion, Airtable, or Google Workspace (your own workspaces, with your access controls). Your lead-enrichment accounts (Apollo, Clearbit, Hunter — credits bill to your plans with each provider). These get connected during setup, or later, when a specific task first needs one.
Cost is not the dividing line — every paid service bills to you either way. What varies is who does the setup. We wire up the supporting services alongside you; you personally hold the ones the outside world reads as yours, like a phone number, an email address, or a payment destination.
Updates and Upgrades
Your Sarudo instance runs on your server, so nothing changes on it unless someone changes it. New capabilities, bug fixes, and reliability improvements are available as support work: you buy a 10-hour block at $50/hour and we apply the upgrade through a safe procedure with a pre-flight backup and automatic rollback on failure. You do not have to take any of them — your instance keeps working exactly as it was handed over. The one thing worth not ignoring is a breaking change in an integration you depend on, because that will eventually stop a workflow. When we know about one, we tell you, and you decide whether to spend the hours.