Security

Safe. Transparent. Under your control.

The agent asks for permission, records every step and can undo its actions. Your data is visible to you alone.

Principles

The agent acts in the open, and your data stays under your control. Here is how it works — from action consent to encryption and backups.

Consent for actions

Before changing data or sending anything to an external service, the agent asks you first.

Action history

You see what the agent did, when, and with what result.

Rollback where rollback exists

Changes to your data are returned to the previous state, with the original values kept in the history. A sent email or a completed payment cannot be recalled — which is why those actions only happen with your approval.

You set the limits

You decide what the agent does on its own and what needs your approval.

You type the secrets

Passwords, two-factor codes and captchas are entered by a human — the agent never asks you to dictate them in chat.

Access to your computer

Commands on your own machine are a separate permission: by default the agent asks every time.

Data protection

We never train models on your data. Only you and the people you choose have access to it.

Where the boundary runs

Organizations are kept apart. Agents inside one organization share an environment — separate agents are not a substitute for access control.

Your team only

Each organization's data is kept separate: no one outside your team can see it.

GDPR compliance

Data is stored on servers in the EU/EEA and never shared with third parties.

Integration keys

Stored encrypted and revoked in one click.

Approvals

What the agent does only with your approval

An approval governs the action ahead of it — it does not undo work already done. That is why the agent asks before, not after.

Sending messages and invitations

Emails, messenger messages, invitations to workspaces.

Publishing to external services

Posts, comments, cards and documents visible outside your team.

Payments and transfers

Payments, transfers, issuing and settling invoices.

Deleting and overwriting data

Removing records and writing over existing values.

Changing access rights

Granting, changing and revoking access — yours and other people's.

Changes in live systems

Actions in systems your team or your clients are using right now.

Accepting terms on your behalf

Agreeing to offers, contracts and policies when signing up anywhere.

What people usually ask about security

Data changes and anything sent to external services go through your consent, and every action is recorded in the history: you always see exactly what the agent did. Within the limits you set, the agent acts on its own — and you can change those limits at any time.

Changes to data, yes: the original values are kept in the action history and the previous state is restored. Irreversible actions — sending, publishing, paying, deleting in an external service — cannot be undone, which is why the agent performs them only after your approval.

No. Your documents and conversations are never used to train models — neither ours nor third-party providers'. Data is used only to carry out your tasks.

Accounts, documents and conversations are stored on GDPR-compliant servers in the EU/EEA. Requests to language models are processed outside the EEA as well — every company involved is listed on the Sub-processors page.

Only you and those you explicitly grant access to. Each organization's data is kept separate — other clients can't see it.

Data is encrypted in transit (TLS) and at rest. Integration keys and tokens are stored separately, in encrypted form.

Backups run automatically and regularly. After a failure the data is restored from the latest copy — only the changes made after it are lost.

Integration keys and tokens are stored encrypted and never shown in plain text. Any key can be revoked in one click.

We'll walk you through how the platform's security works

Contact support