Security and data protection — from the start.
Your agent holds your credentials and does real work on a real server. Here is what protects it: six controls, each an architectural fact rather than a policy.
Six controls, built in.
These aren't promises we try to keep afterwards — each one is how the system is physically put together.
One customer, one machine
No shared runtime and no shared database of your content. A problem on someone else's instance cannot reach yours.
A dedicated virtual machine per customer — no shared runtime, no shared data store.
Credentials encrypted — and we can't show them to you again
Your provider key and bot token are encrypted before storage. There is no "reveal" button anywhere — not in your dashboard and not in our support tools. You can replace or delete them; nobody can read them back.
Encrypted before storage; no reveal endpoint exists in the dashboard or the support tooling.
No remote access to your server
No SSH, no web terminal, no file browser, no arbitrary commands. Your server accepts a fixed list of typed operations — restart, apply configuration, collect a log excerpt — and nothing else.
A fixed command allow-list: restart, apply configuration, collect a sanitised log excerpt.
Your server talks to us, never the reverse
There is no management port open to the internet. The agent on your machine opens an outbound connection to us, so there is nothing exposed to find.
No open management port; the connection is initiated from your server, outbound only.
Your conversations stay on your machine
We collect health metrics — processor, memory, disk, whether the agent is running. We do not collect message content, and a log excerpt is fetched only when you request one, with secrets removed.
Health metrics only; log excerpts on your explicit request, with secrets stripped first.
Everything we do is written down
Configuration changes, restarts, credential updates, and support access are all recorded in an audit trail with a timestamp.
A timestamped audit trail covering configuration, restarts, credential updates, and support access.
What this does not mean.
Your agent sends your messages to whichever AI provider you configured. That traffic leaves your server and is governed by that provider's terms, not ours. Choosing the provider — and deciding what is appropriate to send it — is yours.
We describe our approach as GDPR-aware. We do not hold a certification and we do not claim one. If you need a Data Processing Agreement, ask and we will send the current version.
A server of your own, secured like this.
Get your agent on the machine this page describes — or look at the technology underneath it first.