Your AI's best friend

Everything your AI needs to work on your project. Including the credentials.

Organize instructions, contexts, credentials and scripts in one place. The AI connects through MCP, runs scripts on controlled runners and uses each credential without ever accessing its value.

Works with any MCP-compatible client — Claude, Cursor, VS Code and more. One endpoint per project: iaimigo.com/mcp/p/your-project

The AI uses a credential without accessing its valueRunners on your infra or oursFull audit trail of every runMulti-tenant, multilingual, multi-region
The problem

Your AI already works. What's missing is a proper place for it to work.

Every team repeats the same instructions in every chat, pastes credentials into the conversation and loses the scripts the AI wrote yesterday.

Scattered instructions

Project rules live in old messages, loose files and the head of whoever started it. Every new chat starts from zero.

Credentials in the chat

For the AI to reach a database or an API, someone pastes the password into the conversation. It ends up in logs, histories and the model's context.

Throwaway scripts

The AI writes a useful script, runs it once and it's gone. Nobody knows what ran, with which access, or how to repeat it.

How it works

Three steps between your team and an AI that works safely

Nothing to install in your model. IAImigo sits between the AI and your infrastructure.

Organize

Create projects and register instructions, contexts, credentials and scripts. Decide what applies organization-wide and what belongs to each project, with per-person or per-group visibility.

Connect

Add the project's MCP connector to your AI client. The login is yours (OAuth 2.1), and the AI receives the instructions and the context index as soon as the conversation starts.

Run

When the AI needs to act, it requests a run. A controlled runner injects the credentials, executes the script in isolation, stores the result and records everything in the audit trail.

Features

Four things every AI needs — organized, versioned and access-controlled

Every item has a scope (organization or project), a visibility (project, private or shared) and tags. The AI gets exactly what it is allowed to see.

Instructions

How the AI should behave in the project. Short, always loaded. With tags they become conditional: loaded only when the topic matches.

get_project_instructions

Contexts

What the AI needs to know. Large documents loaded on demand by topic, with a markdown editor and search.

search_contexts · get_context

Credentials

Credentials kept in a vault — ours or your cloud's. The AI knows name and description; the value only reaches the script, inside the runner.

list_secrets (names only)

Scripts

An immutable history of everything that ran, plus a curated catalog of reusable scripts with versions, pins and usage counters.

search_scripts · run_script · get_run
Security

The AI uses a credential without ever accessing its value. Neither does our platform have to.

Security isn't a feature of IAImigo — it's the reason it exists. Every architecture decision starts there.

  • Credentials injected in the runnerthe value goes from the vault straight into the script's process, encrypted end to end. It never passes through the chat or the model's context.
  • Your vault or oursthe platform's OpenBao by default, or AWS Secrets Manager, GCP Secret Manager, Azure Key Vault and Vault in your own account. With a runner on your infra, the value never leaves it.
  • Authorization outside the codeevery access is decided by centralized policies, in the context of whoever asked. Private and shared credentials, custody and break-glass with dual approval.
  • Isolated executionone ephemeral container per run, sandboxed, no network by default and resource limits. mTLS with short-lived certificates between runner and platform.
  • Real audit trailwho asked, which script, which credentials were used (by name), on which runner, with what result. Distinct events for “credential used” and “credential revealed”.
Runners

Run wherever it makes sense: your machine, your server or our platform

One binary, three scopes. You set the order of preference per organization or project — and can switch any of them off.

SCOPE · USER

On your machine

A Docker container on your computer. Ideal for reaching VPNs, SSH, internal databases and local files. Only runs what you asked for yourself.

SCOPE · ORGANIZATION

On your server

A runner on your infrastructure, using your cloud's native identity. Credentials and results never leave your environment.

SCOPE · PLATFORM

On our platform

Nothing to maintain: ephemeral containers isolated per run, a curated image with the most-used tools and explicit limits.

For teams

Built for companies that take access seriously

Roles and permissions

Owner, administrator, security manager, auditor, editor, executor, reader and service accounts — with granular permissions per resource and action.

Social login and SSO

Sign in with Google or Microsoft, or connect your own provider (OIDC, SAML, Entra, Okta) with MFA and automatic provisioning.

Multilingual and time zones

Interface in English, Portuguese and Spanish; timestamps in each person's time zone, with the organization's default.

Usage and retention

Retention classes per script type, usage metering per project and expiration policies applied automatically in storage.

API and webhooks

Everything the UI does is in the API (gRPC and REST). Service accounts with keys and webhooks for the events in your workflow.

Isolation per customer

Database, cache, vault, storage and identity separated per organization. Dedicated instance and regional residency for those who require it.

Pricing

A plan for every team size

We're opening access in waves. Prices will be published at launch — accounts created now get the launch conditions.

Starter

For small teams that want to stop pasting passwords into chats.

Coming soonper organization / month
  • Projects, instructions and contexts
  • Credentials in the platform vault
  • Platform runners and runners on your machine
  • Audit trail and run history
Create account
Most popular

Business

For companies with several teams, projects and environments.

Coming soonper organization / month + usage
  • Everything in Starter
  • Runners on your infrastructure
  • Advanced roles, custody and break-glass
  • SSO with your identity provider
  • Configurable retention and webhooks
Create account

Enterprise

For those who require isolation, data residency and compliance.

Customannual contract
  • Everything in Business
  • Vault and storage in your cloud (BYO)
  • Dedicated instance and region of choice
  • SCIM, SLA and dedicated support
  • Runner source code audit
Talk to us

No credit card required to create an account. Final prices and limits will be published before billing starts.

FAQ

Frequently asked questions

Which AIs does IAImigo work with?

Any client that supports the MCP (Model Context Protocol): Claude (web, desktop and Code), Cursor, VS Code and others. You add the project's connector to the client, sign in and that's it — no need to change model or tool.

Does the AI really use a credential without accessing its value?

Yes. The AI only receives the name and description of the credentials you authorized. When a script needs one of them, the runner fetches the value from the vault and injects it directly into the script's process. The value does not pass through the chat, the model or the returned result.

Do I need to host anything?

No. You can use only the platform runners. If you'd rather have scripts run on your machine or your infrastructure — to reach internal networks or keep credentials in your cloud — just start a runner with one command.

Where is my data stored?

Each organization has its own database, cache, vault and storage, isolated from other customers. The platform is organized in regions: your organization's data lives in the chosen region and is never queried across regions. Enterprise customers can use vault and storage in their own cloud.

What happens when someone leaves the company?

That person's private items go into custody: nobody sees them, but an administrator can transfer ownership (without seeing the value) or delete them. Everything is recorded in the audit trail.

How much does it cost?

Plans and prices will be published at commercial launch. Creating an account is free and requires no card; those who join now get the launch conditions.

IAImigo

Give your AI a proper place to work.

Create your account, connect the first project and never paste a password into a chat again.