DX Heroes AI Platform
AI agents under your control.Every step on record.
AI agents read your documents for you and write them into your systems. You decide what they may touch and where they run, and you have a record of every step.
Runs on your servers or in a European cloud
Start with one process
Nothing gets rebuilt
We built it for our own operations. Today it runs at two companies in the Czech Republic and a bank in Slovakia.
Sample
One step of an agent
From manufacturing
An inquiry arrives by email as a long PDF with pictures and notes.
The agent reads the attachment and extracts over 30 parameters.
It sorts the items by the company's standards and rules.
A technician checks the result and approves it.
The inquiry goes to pricing. Every step is on record.
Your people retype documents instead of doing the work they are good at.
Company knowledge lives in documents: contracts on SharePoint, PDF orders in inboxes, drawings, spreadsheets. Today people carry it into systems by hand.
Operations
People retype documents into systems.
A technician, an accountant or a salesperson reads a PDF and copies numbers into the ERP. When that person is out, the work stops.
Customer
Documents wait, and so does your customer.
An inquiry sits in a queue for a technician. An order waits for someone to retype it.
Security
Nobody knows what AI tools do in your company.
People connect their own AI tools to company data. An overview of who uses what usually appears only after an incident.
Same documents, same systems. The retyping is gone.
Today
The bridge between documents and systems is human hands.
SharePoint & document stores
Inboxes with PDF orders & invoices
Scans & technical drawings
Spreadsheets
People read, retype, forward
Your systems (ERP such as SAP)
SharePoint & document stores
Inboxes with PDF orders & invoices
Scans & technical drawings
Spreadsheets
People read, retype, forward
Your systems (ERP such as SAP)
With the AI Platform
The retyping is gone, and every step leaves a record.
SharePoint & document stores
Inboxes with PDF orders & invoices
Scans & technical drawings
Spreadsheets
Agents
read, extract, answer, enter data
One door for all AI traffic
access, approvals, audit
Your systems (ERP such as SAP)
Report card & evidence
what they did, what it cost, whether it helps
SharePoint & document stores
Inboxes with PDF orders & invoices
Scans & technical drawings
Spreadsheets
Agents
read, extract, answer, enter data
One door for all AI traffic
access, approvals, audit
Your systems (ERP such as SAP)
Report card & evidence
what they did, what it cost, whether it helps
The agent reads, extracts and writes. You approve the exceptions.
The DX Heroes AI Platform gets your documents into your systems without retyping. AI agents read, extract and write them; you decide what they may touch and where they run, and you have a record of every step. It runs on your servers or in a European cloud.
A document arrives
By email, into a shared folder or from a scanner. Nothing changes in how you receive it.
The agent reads and extracts it
Items, parameters, amounts. Unclear cases get flagged and handed to a person.
It passes through one door
Access, approvals and the record live in one place. The agent touches only what it may.
Written into your system
Approved data goes into the ERP or wherever you need it. Every step leaves a record.
What you get
Documents processed the day they arrive. People approve exceptions instead of retyping.
A record of every step. When the auditor asks, you answer from records, not from memory.
Data under your control, on your servers or in a European cloud.
What you need for it
Read access to the systems the work touches. Nothing gets rebuilt.
A decision on where it runs: your servers, or a European cloud.
One person on your side who owns the topic.
A first process to pilot. A pile of PDFs is the usual start.
Half an hour about your first process.
It already runs in manufacturing. It started with a pile of PDFs.
From manufacturing, where it is proven
Inquiries
Inquiries sorted for the technicians
Inquiries arrive by email, sometimes as hundred-page PDFs with pictures and handwritten notes. Technicians used to sort them themselves.
An inquiry arrives by email, often as a long PDF.
The agent sorts the items by standards and company rules.
A technician reviews the worksheet; the agent learns from corrections.
The checked inquiry goes straight to pricing.
>99 %
sorting accuracy, 30+ parameters per inquiry
Read the case study →
Quality control
Products checked against the drawing
A technical drawing sets how far each dimension of a product may deviate.
The input is a drawing with tolerances and a measurement report (PDF).
The agent matches measured values to the drawing's dimensions.
It compares every deviation with the allowed tolerance.
The report flags defective pieces before they move on.
Sensitive drawings must not leave the company, so the agent runs on models operated in the Czech Republic.
In other industries
Knowledge
Answers from your SharePoint
An assistant answers from the documents you already keep on SharePoint and network drives. Every answer links to its source and respects access rights. People find the document in seconds.
Orders
Orders in the system the same day
Customers send orders by email in dozens of formats. The agent reads them and writes them into the ERP; a person confirms only the unclear ones. That typically frees up half to one full-time role of manual work.
AI rollout
An AI assistant for the whole company, not a handful of people.
When a hundred people get an AI tool, it is not enough for each of them to set up their own connection to Slack or other company tools. Through one door, everyone connects under their own identity and IT manages one connection instead of a hundred.
We don't sell what we don't run ourselves.
The DX Heroes AI Platform is not another chatbot over documents, and not a US service keeping your data in a foreign jurisdiction. We built it for our own operations in Prague, and today we deploy it at companies in the Czech Republic and Slovakia.
6 billion
tokens processed across our AI tools in 30 days
100
AI-eNPS of our team, measured by AI Pulse
Our own numbers from a small company, not a benchmark. The platform collects and renders them itself.
Beyond our own use, the core of the platform runs in production in regulated environments: two companies in the Czech Republic and a bank in Slovakia.
„I see up close how DX Heroes run the platform on themselves. Six billion tokens a month is not a marketing number, it is real production traffic. And that is exactly the measurement most companies are missing when they decide about AI.“
Vratislav Kalenda Founder, Applifting
The numbers above are ours. Yours start with a pilot.
The agent works. You decide, and you have it on record.
Runs on your servers or in a European cloud.
Configuration, access and records stay in your databases. No control plane at the vendor.
Access without handing out keys.
The agent gets limited access to what it needs. When someone leaves, you revoke everything in one place.
A record of every step.
You can show at any time who touched what with AI. Records also flow into your security monitoring (SIEM).
Sensitive documents never leave the company.
Where the job requires it, the agent runs on models operated in the Czech Republic.
Data about people only in aggregate.
Measurement serves teams and their growth, not the evaluation of individuals. You control access and retention.
EU AI Act with evidence in hand.
An inventory of tools, an audit trail and reporting per team. Obligations phase in, with the next wave from August 2026; your lawyer maps them, we supply the evidence.
The agent may do only what you allow.
A person runs the pilot, not a ticket.

Prokop Simek
CEO
Leads the first meeting and the pilot proposal. Makes sure the chosen process pays off.

Jakub Vacek
Applied AI Architect
Designs the agents and takes them to production. Deploys the platform at your company and hands it over to your IT.
For your IT and security
From here down we answer how the platform is built and how it holds up in a security review.
One platform, components as you need them.
The platform sits between your people's AI tools and your systems. Each component works on its own; together they cover everything from access control to audit evidence.
AI clients
Tools & MCP servers
AI models
Control plane
DX HeroesDX MCP Gateway
Every AI tool call goes through one governed door.
Team profiles and per-user connections: one connector for the whole company, everyone under their own identity (OAuth 2.1, DCR).
Every tool call recorded, exported via OpenTelemetry and into your SIEM.
Self-hosted on Docker Compose, Kubernetes or OpenShift; wraps a system without an AI connector through its OpenAPI specification.

One readout of MCP traffic health for platform and security teams.
Insight plane
DX HeroesAI Telemetry Hub
One dashboard for what AI costs and whether it pays off.
Collects from the tools teams already use, with no agents on laptops.
Adoption funnel: who has access, who uses AI and who is a power user.
Open source (MIT), metrics with five-year retention in your perimeter.

Cost and ROI next to sentiment: our own internal data, measured by the platform itself.
Employee sentiment
DX HeroesAI Pulse
Numbers show usage. AI Pulse shows whether it helps.
Short Slack questions driven by real activity, with limits so nobody gets flooded.
eNPS, themes and an estimate of hours saved, summarised by an LLM.
A team-level summary, never an evaluation of individuals.

A short question in Slack, answered with one click. That is the entire survey.
Auth plane
DX HeroesAuthLane
Agents get scoped access. People stop handing out passwords and keys.
A credential vault encrypted with AES-256-GCM, with automatic token refresh.
Per-user connections: everyone authorises only their own accounts.
GitHub, Slack, Jira, Notion and more today; Microsoft Entra or SharePoint we set up during rollout.
AI Gateway
The control plane's second door, for calls to AI models (OpenAI, Anthropic). It is part of the rollout, not a separate DX Heroes product. Provider keys stay in the gateway, not on laptops.
How it differs from what you may already be considering.
A regulated EU company weighing AI infrastructure usually shortlists four kinds of alternatives. Here is where each one is strong, and where you hit its limits.
Runs in your perimeter
Governance across clients & servers
AI adoption measurement
Agent auth & credentials
DX Heroes AI Platform
Govern, measure, and authorize in one platform
EU company, and everything including the control plane runs in your perimeter
One control plane across all your AI clients and MCP servers
Native: usage, cost, ROI, and employee sentiment on real traffic
OAuth 2.1 with PKCE and DCR at the gateway, plus the AuthLane credential vault
Hyperscaler agent gateways
e.g. AWS AgentCore, Azure APIM, Google Apigee
EU regions available, but the control plane stays in the vendor's cloud
Strong API governance, MCP support bound to their own stack
Infrastructure telemetry only, no adoption, ROI, or sentiment view
Own identity services, tied to their cloud
US SaaS platforms
e.g. Composio, Arcade, MintMCP
Managed SaaS by default; self-host typically reserved for enterprise tiers, entity under US jurisdiction
Mature gateways and large tool catalogs
Audit logs and security observability, not adoption or sentiment
Strong tool-auth products
EU sovereign platforms
e.g. Frends, STOA
Yes, EU entities with on-prem options
Solid, anchored to each platform's own runtime and scope
Process audit and cost observability, no adoption or sentiment measurement
Inbound auth policies; delegated credential brokering is not the focus
DIY from open source
e.g. ContextForge or Obot plus your own OTel stack
Fully in your perimeter
You build and maintain it as the MCP spec keeps evolving
Infra metrics out of the box; adoption measurement becomes your own project
Available in pieces, integration is on you
DX Heroes AI Platform
Govern, measure, and authorize in one platform
Perimeter
EU company, and everything including the control plane runs in your perimeter
Governance
One control plane across all your AI clients and MCP servers
Adoption measurement
Native: usage, cost, ROI, and employee sentiment on real traffic
Agent access
OAuth 2.1 with PKCE and DCR at the gateway, plus the AuthLane credential vault
Hyperscaler agent gateways
e.g. AWS AgentCore, Azure APIM, Google Apigee
Perimeter
EU regions available, but the control plane stays in the vendor's cloud
Governance
Strong API governance, MCP support bound to their own stack
Adoption measurement
Infrastructure telemetry only, no adoption, ROI, or sentiment view
Agent access
Own identity services, tied to their cloud
US SaaS platforms
e.g. Composio, Arcade, MintMCP
Perimeter
Managed SaaS by default; self-host typically reserved for enterprise tiers, entity under US jurisdiction
Governance
Mature gateways and large tool catalogs
Adoption measurement
Audit logs and security observability, not adoption or sentiment
Agent access
Strong tool-auth products
EU sovereign platforms
e.g. Frends, STOA
Perimeter
Yes, EU entities with on-prem options
Governance
Solid, anchored to each platform's own runtime and scope
Adoption measurement
Process audit and cost observability, no adoption or sentiment measurement
Agent access
Inbound auth policies; delegated credential brokering is not the focus
DIY from open source
e.g. ContextForge or Obot plus your own OTel stack
Perimeter
Fully in your perimeter
Governance
You build and maintain it as the MCP spec keeps evolving
Adoption measurement
Infra metrics out of the box; adoption measurement becomes your own project
Agent access
Available in pieces, integration is on you
When to choose what
If your company is all-in on a single cloud and your data may live there, the hyperscaler gateway is a reasonable default. If you need one governed control plane across clouds, IDEs, and internal tools, running inside your own perimeter, that is what the DX MCP Gateway is built for.
If you only need Copilot numbers, GitHub's built-in dashboards are enough. For engineering benchmarking, measurement-only tools such as Faros AI or DX do a good job. If you want measurement wired into the same layer that governs the traffic, including how people feel about it, that is the Telemetry Hub with AI Pulse.
If you are building a SaaS product that needs tool auth for your customers, developer platforms serve that well. If you are rolling out agents inside a company and refuse to hand out secrets, AuthLane with the gateway keeps credentials in one governed place.
Snapshot of public vendor documentation, July 2026. This market moves fast; we keep the table current. The comparison is category-level and based on public vendor documentation as of July 2026. Verify the details against your requirements; we are happy to help with the mapping.
Same building blocks, different consequences.
Pick a component for each layer and choose where it runs. The score shows right away what it means for your data, costs and vendor dependence.
Not sure where to start?
Pick the preset closest to your situation.
Click a box to see the detail and swap the component.
Switch the views: business, infrastructure, technical. Scenarios live in the technical one.
The builder is a learning model. Bring your assembly to a consultation and we will walk it with you.
Presets
This is a teaching model, not a price list. It shows pricing models and consequences; you get concrete numbers in a consultation.
Every box is clickable. Swap the component or change where it runs.
Live scorecard
Sovereignty verdict
Residency only
Weakest links: Microsoft Entra ID · Azure OpenAI (EU data zone)
Managed-cloud only: Microsoft Entra ID, Azure OpenAI (EU data zone)
Cost model of this assembly. Usage- and token-metered components make monthly costs variable.
Does the stack show whether the AI investment pays off?
2 components with strong vendor dependence in the path.
View
One assembly, three altitudes: business value, where it runs, technical detail.
Scenario
Customer perimeter. Managed-cloud components step outside it.
1 · Your people's AI tools
The tools your people use to work with AI.
2 · Who may sign in
Decides who may use AI at all.
Residency only: An EU region keeps the data in the EU. The vendor is US-domiciled, so the US CLOUD Act still applies. That is residency, not sovereignty.
3 · One door for AI actions
The one door for every AI action; you decide what passes.
4 · Keys to your systems
Hands out keys to your systems and takes them back.
5 · Evidence and measurement
Shows whether AI helps and proves who did what.
6 · How your people feel
Tells you whether people actually feel helped.
7 · What the AI can do
The abilities you allow the AI to have.
8 · Your systems and data
Your systems and data the AI works with.
9 · Model traffic control
One place that controls model usage and spend.
10 · Where answers are computed
The brain that answers; where it runs decides who sees your prompts.
Residency only: An EU region keeps the data in the EU. The vendor is US-domiciled, so the US CLOUD Act still applies. That is residency, not sovereignty.
Happy with your assembly? Bring it to a consultation. We deploy the platform inside your perimeter and help your people use it every day.
Beyond our own use, the gateway runs in production in regulated environments: two enterprises in the Czech Republic and a bank in Slovakia.
How the verdict is computed: US-exposed means a US-domiciled vendor's managed cloud, where an entity under US jurisdiction processes the data. Residency means a US vendor's EU region or EU data boundary. The data sits in the EU, but the vendor remains subject to US law, so residency is not sovereignty. EU-sovereign means on-prem or air-gapped deployment with any vendor, or an EU-domiciled vendor on EU infrastructure. Hyperscaler "sovereign clouds" (AWS European Sovereign Cloud, Microsoft Cloud for Sovereignty, Google S3NS) claim stronger guarantees; this model scores them as residency and notes the option where relevant. The measurement axis rates what a component measures out of the box. Adoption and value can also be measured on open-source telemetry if you build the analytics yourself.
Component capabilities and deployment options were verified against public vendor documentation on 20 August 2026. The market moves fast; we keep the model current.
What we get asked most.
Will the agents replace our people?
No. Agents take over the reading and retyping, the work that keeps your people from what they are good at. People approve exceptions and make the decisions. In the factories where it runs, technicians still price every inquiry; they just no longer sort it by hand first.
Where does our data live?
With you. Configuration, access, records and survey answers stay in your databases, on your servers or in a European cloud of your choice. There is no control plane at the vendor and nothing is sent out.
How long does a pilot take?
Usually two to three months, including the security approval on your side. We start with one process, typically one kind of document. At the end you have an agent running in your environment and numbers to decide the next step.
Do we have to adopt the whole platform at once?
No. Most companies start with either access governance (who may do what) or measurement (who uses AI and what it costs). The components share one data layer, so you add the next one when you need it.
What about systems that have no AI connector yet?
An interface is enough. We load the interface description (OpenAPI) into the platform and it turns it into a tool the agents may call, with the same access rules and record as everything else. Connectors for common Czech accounting, ERP and company registers ship with the platform; we add others during rollout.
Can data about individuals be misused for performance reviews?
We designed the platform for team growth, not for surveillance. Survey answers are aggregated per team, and per-person views exist for coaching and onboarding. Who sees the data and how long it is kept is up to you.
How does the platform help with the EU AI Act?
It supplies the evidence layer: an inventory of AI tools, an audit trail of every call and reporting per team. Obligations phase in, with the next wave from August 2026. It is not a legal service; your lawyer maps what applies to you. We supply the evidence they will need.
How do we start?
Get in touch. In the first half hour we walk through your process and environment. Then we prepare a pilot proposal on your infrastructure, including what we need from your IT. Scope and terms follow what you choose.
AI agents under your control.
Every step on record.
Tell us which document takes the most of your people's time today. We reply within 24 hours and set up half an hour about your first process.
Runs on your servers or in a European cloud
Start with one process
Nothing gets rebuilt

Prokop Simek
CEO
With over 12 years in software engineering, I lead our strategy and sales and advise enterprise teams on AI adoption. My job is to connect business with technology so it actually pays off.