Hostkeep

MCP for Windows Early access

Ask your machines
what happened
last night.

Hostkeep connects your AI assistant to your Windows machines and VMs. It reads the logs, checks the code and runs only the tasks you've allowed, so you get the answer without opening remote desktop.

  • Every project walled off
  • Read-only by default
  • No admin rights, no Hostkeep cloud
A small castle keep on a hill at night, one window lit, a beacon pulsing above it
An ordinary night on vm-2

02:04 · nightly-import exited with code 1

Your assistant has a way in.
You decide how far it goes.

07:31 · the morning after

One question.
A clear answer.

Pick a situation. See what the assistant does with Hostkeep, what gets recorded, and what gets refused.

your assistant · hostkeep @ vm-2connected
  1. The nightly import on vm-2 failed at 02:04. What happened?
  2. project_roots_listvm-23 projects
  3. filesystem_searchtrading-bot · "ERROR|Timeout" in logs/3 matches
  4. filesystem_read_rangelogs/import-10-08.log · lines 1180–121435 lines
  5. git_logtrading-bot · since Monday4 commits
  6. git_diffa41f9c2 · config/feeds.json1 file
  7. AI

    The 02:00 run timed out calling the price feed (log line 1197: TimeoutError after 5000 ms). On Tuesday, commit a41f9c2 “switch price feed” moved to a slower endpoint but kept the 5-second timeout.

    Suggested fix: 30 seconds and one retry. Shall I run the tests first?

  8. Yes, run them.
  9. run_teststrading-bot · unit-tests (fixed task)48 passed
  10. AI

    All 48 tests pass. The fix is a one-line change in config/feeds.json. This project is read-only for me, so the edit is yours to make.

Scope on this machine

project trading-botaccess readtasks unit-tests

What Hostkeep records

  1. 07:31:05project_roots_listok
  2. 07:31:06filesystem_searchok
  3. 07:31:07filesystem_read_rangeok
  4. 07:31:08git_logok
  5. 07:31:09git_diffok
  6. 07:31:41run_testsok

Seven walls

01020304050607

Every call passed all seven checks and was recorded.

6calls
0changes
0refused
Illustrative session. Tool names, scopes and refusal codes are real Hostkeep behavior. Hostkeep has no chat window of its own: your assistant is the interface.
02:30 · engineering evidence

Trust should come with receipts.

Measured on Windows 11.
Every claim has a test behind it.

FIG. 1 · TESTS
192/ 192 pass

Automated tests, one square each. Every fix starts as a failing test.

full suite · Windows 118 OCT 2026E-1
FIG. 2 · CONTAINMENT
0/ 100,000
43,220 folder swaps0 escapes

Outside reads or writes while another process swapped project folders for links as fast as it could.

stress suite8 OCT 2026E-2
FIG. 3 · SOAK
17,766calls
start 141 MB260 MB

One-hour soak test, zero errors. Memory rises while warming up, then stays flat at 255–260 MB.

62 one-minute samples7 OCT 2026E-3
FIG. 4 · SPEED
0.57ms median
p500.57 ms
p950.94 ms
p991.16 ms

Fully contained file read, folder pinning included. 10,000 samples.

local NTFS8 OCT 2026E-4
03:10 · what it's for

Built for the work that breaks at night.

Bots, scrapers, automations and client servers run unattended on Windows. Hostkeep gives your assistant just enough access to answer for them.

07:31Workflow · W1

Diagnose a failed job

Find the cause from the logs, the code and what changed recently, without logging in to the machine.

“Why did last night's import on vm-2 fail?”

filesystem_search · filesystem_read_range · git_log · git_diff

READ-ONLY
07:38Workflow · W2

Collect outputs and logs

Query CSV and JSONL results, read PDFs and SQLite, and summarise what a run produced.

“Summarise today's scraper output and list the failures.”

filesystem_glob · csv_query · jsonl_query · sqlite_query_readonly

COLLECTED
07:46Workflow · W3

Keep clients apart

Each client is its own project, with its own permissions and tasks. The assistant works inside one wall at a time.

“Run the unit tests for the Acme project only.”

project_roots_list · project_capabilities · run_tests · run_allowed_command

WALLED
Under the hood

The full toolbox: 63 tools

38 on by default. The rest stay off until you switch them on.

Explore the tools
read-onlycan make changesoff until enabled

Files 17

  • filesystem_list
  • filesystem_read
  • filesystem_read_range
  • filesystem_read_bytes
  • filesystem_batch_read
  • filesystem_stat
  • filesystem_glob
  • filesystem_hash
  • filesystem_compare
  • filesystem_search
  • filesystem_write
  • filesystem_write_base64
  • filesystem_edit
  • filesystem_copy
  • filesystem_move
  • filesystem_delete
  • filesystem_mkdir

Projects 3

  • project_roots_list
  • project_capabilities
  • temporary_workspace_create

Git 4

  • git_status
  • git_diff
  • git_log
  • git_checkpoint

Tests & tasks 2

  • run_tests
  • run_allowed_command

Web 1

  • browser_screenshot

Data 4

  • csv_query
  • jsonl_query
  • dataset_profile
  • sqlite_query_readonly

Documents 3

  • pdf_extract_text
  • image_ocr
  • media_probe

Archives 4

  • archive_list
  • archive_read_entry
  • archive_extract
  • archive_create

Analysis jobs 6

  • analysis_job_start
  • analysis_job_status
  • analysis_job_logs
  • analysis_job_artifacts
  • analysis_job_cancel
  • analysis_job_cleanup

Fetch & export 4

  • http_fetch_text
  • asset_download
  • filesystem_export
  • analysis_job_artifact_export

Host & desktop 15

  • host_process_start, host_powershell_start and 6 more
  • host_desktop_* (7 tools)
04:00 · how it works

Draw the walls once. Ask forever.

Hostkeep is one small program on each machine. You name the folders it may see and the exact tasks it may run. Your assistant connects over MCP, the open standard assistants use to work with tools.

  1. Install on the machine

    Runs in the background as your normal Windows user. No admin rights, nothing exposed to the network: it listens on 127.0.0.1, and remote access goes through a tunnel you control.

  2. Name projects and tasks

    Each project is a folder with its own permissions. Tasks are commands you write down in advance, with typed parameters.

  3. Connect your assistant

    Point any MCP client that supports streamable HTTP at the machine, with an access token kept in an environment variable. Then just ask.

config/local.jsonreal format
{
  "host": "127.0.0.1",
  "auth": { "tokenEnv": "HOSTKEEP_TOKEN" },
  "projectRoots": [
    { "id": "trading-bot", "path": "D:\\bots\\trading",
      "allowWrite": false },
    { "id": "client-acme", "path": "D:\\clients\\acme",
      "allowWrite": true, "writablePaths": ["reports"] }
  ],
  "commands": [
    { "id": "unit-tests", "executable": "npm", "args": ["test"],
      "rootIds": ["trading-bot"], "testCommand": true }
  ],
  "hostAccess": { "enabled": false }
}
AssistantAsksA tool call over MCP
GateWho are you?Token, host name, rate limit
PolicyIs it allowed?Project, read or write, task
ExecuteDo it safelyPinned files, fixed commands
RecordWrite it downHash-chained activity log
AnswerBack to youOnly what the project allows
04:40 · security model

Seven walls. None of them trust the AI.

An assistant can be confused, or tricked by text hidden in a file it reads. So every protection is enforced in code on your machine, not by asking the assistant to behave. Each wall names the code that enforces it and the test that proves it.

Security plan of the keepSeven concentric walls around the keep. A request enters through the gates on the south side. An attempt to reach another client's folder from inside is stopped at wall 03. 7 INDEPENDENT CHECKS · NONE TRUST THE AINKEEPTOKEN + HOST CHECKED../client-zen/.envREFUSED · PATH_OUTSIDE_ROOT01020304050607REQUEST PATHREFUSEDWALL (CHECK)HOSTKEEPSECURITY PLAN · SHEET S-1SCALE NTSREV 2026-10-08
  1. WALL 01

    A locked gate

    Every request needs your access token and an allowed host name, and is rate-limited, before its body is even read.

    CODE src/server.mjsS-01TEST unauthenticated bodies rejected before parsing
  2. WALL 02

    Only what you switch on

    Tool families you haven't enabled don't exist for the assistant. They're never even listed.

    CODE src/server.mjsS-02TEST disabled families absent from tools/list
  3. WALL 03

    Walled-off projects

    File reads and writes go through a worker that pins every folder with an open handle and opens files relative to it. A path can't be redirected outside the project, even mid-operation.

    CODE scripts/windows-file-io-*.csS-03TEST 100,000-operation race, 0 outside access
  4. WALL 04

    Read-only by default

    Writing is switched on per project and can be limited to sub-folders. Control files such as .git stay protected even in writable projects.

    CODE src/security.mjsS-04TEST protected paths reject every change
  5. WALL 05

    Tasks, not a shell

    The assistant runs commands you defined in advance, with typed parameters that can't smuggle in extra options. Git never runs repository-defined hooks or programs.

    CODE src/command-parameters.mjs · src/safe-git.mjsS-05TEST option-like values rejected before start
  6. WALL 06

    Secrets stay home

    Programs Hostkeep starts get a cleaned environment without your token. Outbound downloads are off by default; when enabled, private network addresses are refused and every redirect is re-checked.

    CODE src/child-environment.mjs · src/outbound.mjsS-06TEST every process route withholds credentials
  7. WALL 07

    Everything on the record

    Every call is logged without file contents or secrets, in a hash-chained log that shows if a record is edited or removed. If logging breaks, new changes are refused until it recovers.

    CODE src/audit.mjsS-07TEST edited or deleted records are reported

We publish what isn't finished. Human approval before changes run, a separate key per client, and handle-pinning for listing and search tools are still on the roadmap, and listed as known gaps until then. Read the full security model →

05:20 · how it's built

Claude designs. Agents build. Evidence decides.

Hostkeep is built AI-first. Claude acts as architect and security reviewer: it writes the specs and decisions, and reviews every change. Coding agents implement against those specs. Every decision is written down with the evidence behind it.

How Hostkeep is built: Fay sets goals, Claude writes specs and reviews security, coding agents implement, gates produce evidence, Claude approves or correctsgoalswritten spectests firstevidenceFayproduct · decisionsClaudearchitecture · specs · reviewCoding agentsimplement to specGates192 tests · stress · soakNothing mergeswithout evidence.
D5Decision · containment

Path checks can be raced. Pin the folders instead.

A stress test showed that checking a path, then opening it, leaves a gap a fast folder swap can slip through. Checks stayed as a first filter, and a dedicated worker now holds every folder open while it works.

→ 100,000 operations, 0 outside access

DECIDED
D8Decision · containment

Open everything relative to what you already hold.

The first version still opened the final file by its full name. Now every step opens relative to a handle the worker holds, and Windows itself refuses to follow a folder that was swapped for a link.

→ swapped folders refused on C: and D:

DECIDED
C3Decision · activity log

One failed log write must never silence the log.

Review found that a single failed write could stop all later records. Now each write fails alone, busy files are retried, and while logging is down, new changes are refused before they run.

→ 11 recovery properties, all passing

DECIDED
runs on Windows 11runtime Node.js 22 LTSprotocol MCP 2025-11-25native layer NT handle APIsdependencies few, all pinned
05:45 · roadmap

What we're building toward.

Our roadmap focuses on giving you more control, making assistants easier to connect, and simplifying everyday use.

  • More control

    Human approval

    Approve changes and tasks from a local page or your phone, with a separate access key for each client.

  • Easier connections

    Web assistants

    OAuth sign-in so web assistants such as claude.ai and ChatGPT can connect to your machines.

  • Simpler setup

    One-click install

    A guided installer, setup page, diagnostic checks and signed releases.

  • Everyday use

    A small-team pilot

    A pilot with three to five teams, focused on time saved and fewer remote desktop sessions.

06:40 · why it exists

“I run a trading system on a Windows VM. Every time something broke overnight, I had to open remote desktop and dig. I wanted to just ask, from wherever my assistant runs. So I built the bridge, and then I made it safe enough to hand to someone else.”

FayFounder, Hostkeep
One week on my own trading VM, earlier private version
4,400+AI tool calls
  • All other tools≈ 3,600
  • Unrestricted PowerShell799
  • Fixed, pre-defined tasks4

Almost one call in five needed full PowerShell, because nothing safer existed between read-only and full control. Hostkeep is built to be that middle ground.

07:05 · questions

Good to know.

What exactly is Hostkeep?

A small program that runs on a Windows machine or VM and lets an AI assistant work on it through the Model Context Protocol (MCP). It can read logs, search code, query data and run tasks you defined, inside project folders you choose.

Where does my data go?

There is no Hostkeep cloud. Hostkeep runs on your machine and answers your assistant directly. What the assistant reads goes to the AI provider you chose, and nowhere else.

Which assistants can use it?

Assistants that connect to remote MCP servers with an access token, such as command-line coding agents, can connect today. Web assistants such as claude.ai and ChatGPT need OAuth sign-in, which is on the roadmap. A verified compatibility list ships with that release.

How is it different from remote desktop or IT management tools?

Remote desktop gives a person the whole screen. IT management suites manage fleets for IT departments. Hostkeep gives your assistant a narrow, recorded view of specific projects, so "what went wrong?" takes one message instead of a login session.

How is it different from MCP servers that control a computer?

Most give the assistant the whole machine and trust it to behave. Hostkeep starts from projects and permissions, and its protections are enforced in code, so they hold even if the assistant is tricked.

Can the AI run anything it wants?

No. By default it can only read inside the projects you named. Writing is switched on per project, control files stay protected, and it can only run commands you defined in advance, with checked parameters. Broader host access exists as a separate, advanced option that is off by default.

Does it need administrator rights?

No. Hostkeep runs as your normal Windows user, in the background.

07:30 · MORNING

You already know what broke.

Hostkeep is in early access for small teams who run bots, automations or client servers on Windows. Tell me what you run and how you handle failures today.

fay@hostkeep.tech