Trust
You are handing this thing your inbox.
An assistant that can read your mail is a serious thing to install. Here is what we do about that — and underneath it, what we have not done yet.
- You grant access, and you can take it back
- Connections to Gmail, Calendar and Slack are made through the provider's own consent screen. We never ask for your password. You can revoke our access from your Google or Slack account at any time, without talking to us, and the assistant stops immediately.
- Credentials are encrypted at rest
- OAuth tokens are stored encrypted with a key held separately from the database. A dump of the database on its own does not yield working access to anyone's mailbox.
- Nothing outbound happens without a gate
- Every action that leaves your company is verified, checked against policy, and — until you promote it — held for your approval. This is a security property before it is a product feature: the blast radius of a model mistake is a draft you decline.
- Everything is written down
- Every run records what was proposed, what was checked, what you decided, and what was executed. If you need to answer 'what did this thing do on Tuesday', there is a record rather than a reconstruction.
- Your data is not training data
- We do not train models on your mail, your calendar, or your documents. Your assistant's memory of your preferences is yours, isolated to your company, and exportable.
- Least access, by design
- The assistant requests the narrowest scopes that let it do its job, and each skill can only reach the tools that skill needs.
What we have not done yet
The honest list
We are early, and pretending otherwise on a security page would be a strange way to earn your trust. If any of these blocks your company, say so — it tells us what to build next.
- We are not SOC 2 certified. We have not started an audit, and we will say so here when we do.
- We have not had an external penetration test.
- We do not yet offer SSO, SCIM provisioning, or customer-managed encryption keys.
- We have no published uptime SLA.
Reporting a problem
Found something? Tell us directly.
Email security@theagenticworkforce.com. A founder reads it, you will hear back within two working days, and we will not threaten you for looking.
Other ways to reach us