Security
Safe. Transparent. Under your control.
The agent asks for permission, records every step and can undo its actions. Your data is visible to you alone.
The agent acts in the open, and your data stays under your control. Here is how it works — from action consent to encryption and backups.
Consent for actions
Before changing data or sending anything to an external service, the agent asks you first.
Action history
You see what the agent did, when, and with what result.
Rollback where rollback exists
Changes to your data are returned to the previous state, with the original values kept in the history. A sent email or a completed payment cannot be recalled — which is why those actions only happen with your approval.
You set the limits
You decide what the agent does on its own and what needs your approval.
You type the secrets
Passwords, two-factor codes and captchas are entered by a human — the agent never asks you to dictate them in chat.
Access to your computer
Commands on your own machine are a separate permission: by default the agent asks every time.
Data protection
We never train models on your data. Only you and the people you choose have access to it.
Where the boundary runs
Organizations are kept apart. Agents inside one organization share an environment — separate agents are not a substitute for access control.
Your team only
Each organization's data is kept separate: no one outside your team can see it.
GDPR compliance
Data is stored on servers in the EU/EEA and never shared with third parties.
Integration keys
Stored encrypted and revoked in one click.
Approvals
What the agent does only with your approval
An approval governs the action ahead of it — it does not undo work already done. That is why the agent asks before, not after.
Sending messages and invitations
Emails, messenger messages, invitations to workspaces.
Publishing to external services
Posts, comments, cards and documents visible outside your team.
Payments and transfers
Payments, transfers, issuing and settling invoices.
Deleting and overwriting data
Removing records and writing over existing values.
Changing access rights
Granting, changing and revoking access — yours and other people's.
Changes in live systems
Actions in systems your team or your clients are using right now.
Accepting terms on your behalf
Agreeing to offers, contracts and policies when signing up anywhere.
What people usually ask about security
Data changes and anything sent to external services go through your consent, and every action is recorded in the history: you always see exactly what the agent did. Within the limits you set, the agent acts on its own — and you can change those limits at any time.
Changes to data, yes: the original values are kept in the action history and the previous state is restored. Irreversible actions — sending, publishing, paying, deleting in an external service — cannot be undone, which is why the agent performs them only after your approval.
No. Your documents and conversations are never used to train models — neither ours nor third-party providers'. Data is used only to carry out your tasks.
Accounts, documents and conversations are stored on GDPR-compliant servers in the EU/EEA. Requests to language models are processed outside the EEA as well — every company involved is listed on the Sub-processors page.
Only you and those you explicitly grant access to. Each organization's data is kept separate — other clients can't see it.
Data is encrypted in transit (TLS) and at rest. Integration keys and tokens are stored separately, in encrypted form.
Backups run automatically and regularly. After a failure the data is restored from the latest copy — only the changes made after it are lost.
Integration keys and tokens are stored encrypted and never shown in plain text. Any key can be revoked in one click.