There is no vector database, and that is deliberate
All the content on this site — 30 pages in two languages — is about 13,000 tokens. The model takes 200,000. It fits whole in every request, so there is nothing to chunk, index or retrieve. That removes the classic failure mode of these agents: retrieval pulls the wrong fragment and the agent confidently tells you something untrue. Here it always has everything in front of it. Measuring before building saved an entire piece of infrastructure.
Caching is what makes this cheap
That content travels identically in every request, so it gets cached: each conversation re-reads about 10,000 tokens that cost a tenth of their normal price and do not count against the per-minute rate limit. Without it, an agent that reads the whole site on every message would be expensive. With it, it costs cents.
One single tool, and none of them dangerous
Besides answering, the agent can do exactly one thing: record your details if you tell it you want us to write to you. Nothing else. It does not delete, charge, promise or touch any system. Anyone who opens this site writes this model's input, so giving it broad capabilities would hand out attack surface for nothing in return.
What the model says is validated before it is stored
When the agent records a contact, those fields do not go into the database as they come: they go through the same validation as a public form, because in practice that is what they are. A malformed email or an oversized field is rejected there. Seven automated tests cover that boundary specifically.
What happens when something fails
If the database does not answer, the agent still replies and points you to the form; the failure is logged on our side. Storing analytics must never break someone's page. It is the same rule we apply on client projects: the incidental does not take down the essential.
There is no API key in this project
The server authenticates against the model with its own infrastructure's managed identity. There is no secret to store, rotate or leak. One credential fewer is one failure mode fewer, and this very project had already lost deployments to expired credentials.