Four rules we build to.
They are not aspirations. Each one is enforced somewhere in the product — in where the data sits, in code the AI cannot argue past, in a ledger, and in what we are willing to print on this site.
It runs on your device.
The AI runs on a box in the owner's house or on their own machine. What it learns about them — the accounts, the habits, the half-finished jobs — is written down where they are, not where we are. It stays for years and it never becomes anyone's training data, ours included. Every customer's work and credentials are isolated from every other customer's by the infrastructure, not by a promise in a policy.
It acts only inside lines you set.
Anything that leaves the building — an email, a payment, a post under the owner's name — waits for their word by default, with a spend cap over it and a stop that works mid-task. The approvals loosen only as far as the owner loosens them, per kind of action. The lines are enforced in code rather than in the prompt, so the AI cannot argue its way past them and neither can anyone talking to it.
Every action leaves a receipt.
Every action an AI takes is appended to a ledger the owner can read and export: what it did, where it did it, what it cost, and what came back — including the failures. Work you can verify, not work the model says it did. It is the oldest rule in the company and the reason anything on this site can be dated and checked.
We say what we have shown.
A number appears on this site only with the file it came out of. When a result has two honest denominators we print both, and when a run went badly we publish that too — a benchmark quoted only on the tasks it won is a sales page, not a result. Where an artefact is real but not yet public, we say so instead of linking something that looks like proof.
What these rules have produced so far is on what we have shown. What our AI does on other people's websites is written down here.