HeliumHelium AI

Your Dedicated VM

Every Hermes subscriber gets a dedicated AWS Lightsail VM. This is not a shared container — it's your own isolated server.

What you getWhat you don't share
Your own VM (Lightsail instance)Compute with other users
Your own memory filesAgent state or conversation history
Your own tool connections (Gmail, Slack…)OAuth tokens or credentials
Your own bot tokenTelegram bot identity
Your own encryption keysSigning keys or mTLS certificates

Security guarantees

  • No public IP on your VM
  • No SSH from Helium — your agent pulls its own config
  • LLM keys never on your VM — all model calls go through a central gateway
  • OAuth tokens never on your VM — decrypted in-memory in a separate service per call

If any provisioning step fails, the system automatically rolls back, cleans up all resources, and issues a full Stripe refund. You'll never be charged for a failed provision.