What we’ve built, and what we haven’t yet.

We sit between your agents and your money, so this page starts with what we haven’t done yet. Every other line on it is checked against the code.

The pack answers the usual questionnaire: architecture, access control, incident response, continuity and sub-processors. Free, and no form.

What this deployment enforces.

Each line is checked against the code; the controls this deployment reports about itself are in trust.json.

Evidence you can check

A hash-chained ledger (SHA-256), written before each response goes back, with Ed25519-signed receipts and checkpoints that verify offline against the published keys. How to verify offline

Secrets sealed at rest

Provider keys, single sign-on secrets, connection tokens and vault fields are sealed with AES-256-GCM, each bound to what it belongs to. The database file as a whole is not encrypted by the application. The threat model

How people sign in

OpenID Connect for Okta, Microsoft Entra and Google Workspace, SAML 2.0 per workspace, SCIM 2.0 provisioning, and authenticator apps and passkeys, which a workspace can require for everyone. Workspace single sign-on

Step-up for big decisions

Approving above your line, releasing personal data or changing security settings needs a fresh proof of who is at the keyboard from the last 5 minutes. Identity and access

How we stop an agent, and who can start it again

One press refuses what the agent asks, voids its receipts and cancels what it was waiting on, across the MCP proxy, the model gateway and agent cards. Who can lift the stop depends on the hold, and after an incident it takes a second person. Through the builders and the SDKs, it is a check the agent’s own code asks for. The kill switch

Prompts stay yours

Prompts and answers are kept as SHA-256 fingerprints, not text, unless you choose otherwise. Requests go to your own provider under your own key, and nothing trains a model. This deployment in trust.json

Where it runs

The hosted service runs on Fly.io in the EU (Frankfurt, Germany). Enterprise can run inside your own cloud, which adds no sub-processor at all. Sub-processors

Check a receipt without us.

This one is in the real format, signed with a demonstration key whose public half is in the page. Change the amount, then verify it: your browser does the check, not our server.

ReceiptEd25519, demonstration key
Paid to
Currency
Approved
Priya Shah approved at 09:43 in SlackFinance opsSupplier invoices
Show signature
kid  jCkF71_Nhw...wMwg
sig  PlClQ_-ESaUQ...-3BuAA
prev 1717cf...ec9e
hash b40fe7...07fa

Change the amount, then verify.

Ask for a document.

What a reviewer usually asks for, where each one stands on 7 October 2026, and how to get it.

Documents for a security review, with their status
DocumentWhere it standsGet it
Security packAvailable now, free and with no formDownload
trust.jsonLive, read from this deployment’s own configurationOpen
Sub-processor listPublishedRead it
Data Processing AgreementOn request while the registered company details are finishedAsk for it
Privacy noticeOn request while the registered company details are finishedAsk for it
Terms of serviceOn request while the registered company details are finishedAsk for it
Penetration test letterNot yet: no independent firm has tested the serviceNot yet
SOC 2 reportPlanned; we hold none todayNot yet

Found a problem? Use the security form; a founder acknowledges every report within two working days.

Let your agents ask first, right in Slack.

Or in Teams, or by email. It takes about two minutes to start, it’s free for three agents, and we never take a share of spend.