SECURITY · FOR YOU AND YOUR IT
What it read, what it wrote, in which system, at what time, and every question a person answered, with their name on it. Nothing is edited after the fact. Your data stays in your systems; we hold the process. This page is what your IT will ask for.
Get your agentevery desk has one · nothing is deleted · people’s decisions are on it too · kept for as long as you are a customer
WHAT THE TIMELINE ANSWERS
WHERE THINGS LIVE
Nothing about your business is copied into a database of ours. The agent reads a record, acts on it, writes the result back, and keeps only the log of having done so.
{{ p.d }}
ACCESS
Read-only where reading is enough. One mailbox, not the domain. The bank is read, never paid from. Every connection names who granted it and when, and your IT can pull it without asking us.
KEYS
API keys and passwords are encrypted the moment you save them. The value is placed in your container only for the run that needs it. An agent calls a connection by name; the platform opens the door. The key itself never appears in a prompt, a log or a chat.
THE MODELS
Where a job needs an agent, the document goes to Anthropic’s Claude models under a business agreement: no training on your data, and retention only as those terms allow. A job that runs as a script sends nothing to a model at all.
WHAT AN AGENT NEVER DOES
Everything else an agent does is written in a plan you approved and can read. These seven are in no plan we build, and the plan is the only thing an agent may act on.
FOR YOUR IT · THE SHORT VERSION
Send this section to whoever signs off on vendors. The long version, with the data processing agreement, sub-processors and incident process, is one e-mail away.
YOU CAN LEAVE
On the day you stop, you get every plan in plain language, every connection listed, and the full run log. Your container is deleted within 30 days and we confirm it in writing.