Vora
A chat interface where trust is a designed surface.
Services
- Strategy & UX design
- Brand identity
- UI design
Deliverables
- Design system
- Production-ready interactive prototype


About VORA
Privacy-first self-hosted AI
Vora is a digital sovereignty company whose mission is to help people reclaim their digital lives. The first product is Aegis, a self-hosted AI server and operating system that runs on hardware the customer owns. Built by leading cryptographers, Aegis leverages a secure kernel that makes prompt injection structurally impossible, enabling a more personal and private AI experience than ever before. This prototype explores what the chat workspace for that product should be.
The problem
Calm, with your entire digital life inside
Vora's brand is a promise of calm in your digital life. The product underneath that promise is anything but small: a self-hosted AI meant to house your files, your conversations, your memory, and agents doing real work on your behalf. The design challenge was holding both at once, an interface that feels calm while being powerful enough to live in.
Two specific problems fell out of that. The first is the security story. Self-hosting is the entire pitch, your data on your hardware, and an interface can't say that once during onboarding and then look like every other chat app. The UI has to reinforce it continuously, and most of all at the moments data actually moves. The second is structure. Vora isn't a pile of dated, disposable sessions; there's a single persistent agent that serves as your primary point of contact, with topic-scoped chats and channels around it. That hierarchy has to be immediately legible, or the calm collapses into confusion about where anything lives.
The tension is that calm interfaces usually get there by hiding things, and a sovereignty product can't hide exactly the things that matter: data movement and agent activity. So the prototype's premise is progressive disclosure rather than concealment. Conversation is a workspace, agency is legible, and consent is a first-class interaction.
Making security visible
The egress checkpoint
Self-hosting's promise is only as good as the moments data leaves the box. Every assistant eventually needs to send something out, an email or a web search, and in a normal app that moment is invisible: you find out what left by trusting that it went well. For a sovereignty product that moment is the test, so the prototype treats it as a checkpoint instead of a background event.
When an agent needs to send anything off the device, a card shows the destination, the exact payload, and a "Stays on your device / Leaves your device" split, with three-way consent: Deny, Send once, Always allow. Sensitive tokens become tappable redaction chips, so you can strip a revenue figure out of an email at the moment of decision. For email, the draft is the payload; the fields are editable in the card, so there's no gap between preview and reality.
After you decide, every label flips tense: "Stays" becomes "Stayed," "What's being sent" becomes "What was sent." Past-tense UI is the difference between describing reality and describing intentions. Agent activity stays compact (a working line with timer and token counters, expandable per agent), nothing touches the web before consent, and agents ask one clarifying question rather than guessing.
Dynamic UI elements
Decisions you tap instead of type
A lot of what people type at chatbots is really a selection, and typing a selection is the worst of both worlds: the person has to compose an answer, the model has to parse it back into a choice, and any ambiguity costs a round trip of clarification. So the prototype renders decisions as interactive cards in the transcript: button groups, editable email drafts, time-slot pickers, product cards with thumbnails. On submit the card locks with a staggered confirm animation and hands the structured choice back to the model, with nothing lost in translation.
There's a trust argument underneath the speed argument. A preference buried in a typed sentence is something the model inferred; a tapped option is something you selected, locked into the transcript as an inspectable record of what was asked and what you chose. For a product about staying in control of your digital life, that difference matters, and it's calmer too: a tap is a smaller demand on your attention than a sentence.
Multi-step questions render as one growing container, each answered step collapsing to a checkmark and a one-line summary, with escape hatches throughout: Skip, an inline "chat about it" option, or replying in the composer to dismiss the sequence. Pending decisions collect in a To Do pane scoped to the current chat. Structured input is faster, but the design problem is keeping it optional; forcing people through a wizard would recreate the phone-tree feeling that makes chat appealing in the first place, so everything here can be answered by typing instead.


Slack-style messaging
Conversation as a workspace
Conventional chatbot bubbles frame the exchange as a person versus an interface, with every session disposable. That framing fights what Vora is: a persistent assistant you live with.
So the chat design borrows from Slack-style team chat instead. Slack's approach (avatar-gutter rows, sender headers, hover toolbars) frames the exchange as two colleagues in a shared space, and people already know its ergonomics from work. Vora is built around a primary persistent chat with your named AI assistant; around it sit topic chats and channels, which are scoped and disposable.
Threads are where the colleague model pays off. Any message can open a thread in a resizable side pane, so a tangent or a sub-agent's work runs beside the main line instead of flooding it; threaded messages show "N replies · last reply 2h," and an artifact opened from a thread opens beside the thread rather than replacing it. The main transcript stays calm while the work happens in the margins, which is how a good team channel feels.
The colleague metaphor doesn't mean one endless scroll, though. Dedicated chats and channels preserve space to organize work around a specific topic, and the transcript feeds them: any message can fork into a new standalone or channel chat, with a model picking the relevant turn range and titling it, a fork marker at the origin, and a "Forked from" back-link that scrolls to the source. The primary chat holds the relationship; channels hold the work.


Memory management
Memory you can audit
Chatbots with memory almost never show their work. Vora's system offers provenance on every memory: which chat it came from, when, and how often it's been retrieved. We give users the tools they need to prune memories as they pile up, with in-line editing, deletion, sorting, filtering, and grouping. When a memory gets saved mid-conversation, a quiet system-log toast ("memory · <fact>") says so in real time. Incognito chats close the loop from the other side: an eye-off toggle, a hidden sidebar row, and leaving the chat erases it without a trace.
Outcome
An interface that tells the truth
The measure I designed for: a person can watch an agent work, understand what it wants to do, edit exactly what leaves their machine, and verify afterward that the interface told the truth.
Want to test it out? Try the live prototype.
Live PrototypeContact
Fill out the form and I’ll get back to you ASAP. Or email me directly at jesse.bisignano@gmail.com.









