Our products · AI desktop app

Co-Help

Co-Help is a desktop app we designed, built, and run. It listens to a live interview or meeting, transcribes it, and races several AI models in parallel to put a well-formed answer on a private on-screen overlay — with the user's data kept on their own machine.

Homepage of co-help.com with the headline Your real-time AI interview co-pilot
Screenshot of the public homepage, captured by Techtonic Innovations on September 21, 2026.

The product and the goal

In a live conversation, a helpful answer that arrives ten seconds late is no help at all. Co-Help's goal is speed without setup: install the app, sign in, and get transcription and AI answers during a Zoom, Teams, or Meet call — no API keys, no provider accounts to configure.

The challenge

Three constraints pulled against each other. Latency: any single AI provider can be slow or down at the worst moment. Security: a desktop app can't safely ship provider API keys to every user's machine. Privacy: transcripts, resumes, and notes are personal, and shouldn't sit on our servers.

What we built

An Electron app with separate windows for sign-in, a three-step setup wizard, the live overlay, session reports, and an owner-only admin dashboard — plus a managed backend and a marketing site.

  • A click-through overlay window that stays on top while you work in other apps, with the operating system's screen-capture protection enabled on it.
  • System-audio capture with silence detection, so both sides of a call are transcribed; transcription runs server-side on Groq's Whisper endpoint.
  • Screenshot Q&A for code, diagrams, or shared content, routed only to vision-capable models.
  • A personal knowledge base built from uploaded PDF, Word, and text files or fetched web pages, so answers draw on the user's own background.
  • Stripe checkout for one-time, monthly, and annual plans, and auto-updates from GitHub Releases with a server-enforced minimum version.

Architecture: a parallel model race

With managed access, questions go to our API on Google Cloud Run. It holds the provider keys in Secret Manager, so users need no keys of their own and none ship in the app. Requests pick a tier — fast, balanced, or deep — and the server fires every configured provider model in that tier at once, returns the first valid answer (Promise.any), and cancels the rest with an AbortController. The API races 12 server-pinned models from six providers in three tiers: OpenAI, Anthropic, Google Gemini, Groq, DeepSeek, and Mistral.

Clients can't request arbitrary models — tiers map to server-pinned models — and output is capped at 4,096 tokens per call to bound cost. Access uses opaque bearer tokens checked against Firestore with a 60-second cache, rate limits apply per token and per plan, and Stripe webhooks activate, cancel, or refund tokens. Provider error messages are reduced to safe codes before logging, because they can echo request data.

Local-first privacy and security hardening

The user's profile, conversations, transcripts, and knowledge base are stored on their own device, not on our servers; license and GitHub tokens are encrypted with the operating system's credential store, and passwords are hashed with scrypt. The account server keeps only the basics needed for sign-in and billing.

The desktop app runs every window with context isolation, sandboxing, and Node integration off; the renderer reaches the main process only through an allowlisted IPC bridge. A tested SSRF guard blocks the URL-fetch feature from reaching local files, loopback, private networks, cloud metadata addresses, or URLs with embedded credentials, and saved HTML reports pass through a sanitizer. The API container runs as a non-root user, and the CI pipeline runs syntax checks, unit tests, npm audit, installer-content verification, and Docker builds.

SEO and the marketing site

co-help.com is a static site served by nginx with clean URLs, permanent redirects for trailing slashes and .html paths, and a real 404 page. It adds landing pages for Zoom, Teams, Google Meet, coding, system-design, and Mac use, competitor comparison pages, and a blog; SoftwareApplication, FAQPage, and Organization structured data; an llms.txt; and a robots.txt that welcomes AI answer-engine crawlers. It sends a strict Content-Security-Policy, preload-ready HSTS, and frame-ancestors protection.

Co-Help is a working example of our AI development and custom software practice — and of the multi-provider routing we bring to client AI agents.

Results

  • Live at co-help.com; the current release is v5.11.1 for Windows 10/11 and macOS 11+.
  • Scores 98/100 on our own website audit tool (measured September 21, 2026).
  • The live sitemap lists 17 URLs, and the homepage is served with a strict Content-Security-Policy and preload-ready HSTS.
  • 114 commits in the desktop app repository between February 13 and September 11, 2026.

Facts verified against the project's repository and live site. Past results don't guarantee future results; every project is different.

More case studies

All case studies