The Brain / Security

It acts only as the person who signed in.

Nothing in a document, an email, or the AI's own output can change who that is, or approve an action on their behalf.

Book a demo How it is built

01 · The threat we designed against

A hidden instruction cannot change who is asking

The attack that matters is a sentence hidden in a document that talks the AI into naming a different company or user; the proof page holds what is not proven.

01

Who it acts as comes from the sign-in

The person, the company and every credential are taken from the signed-in session, and stripped from whatever the AI writes.

02

It cannot approve its own action

A yes only counts when a person clicked it; an approval written by the AI is not one.

03

Credentials are read at the moment of use

Never cached at start, so a revoked credential takes effect at the next call, not the next restart.

02 · Reading and changing

What it may read, and what it may change on its own

Your data

Reads stay inside your company's own data

Every record and remembered fact is stamped with the company it belongs to, and a read stays inside that stamp.

The unknown

An uncheckable stamp answers unknown, never pass

No query runs without it.

The stop

71 of 287 actions stop for a person

Everything that sends, deletes or shares, by category, so a new action of that kind stops from the day it exists.

The claim

What it says is checked against what happened

It checks the change landed before telling you, and its reply against what the tools returned.

03 · The questionnaire

The five questions a review asks

The questionWhat we can showWhat we cannot
Who is the system acting asThe person who signed in, with identity stripped from the AI's output firstA per-user mirror of the permissions in your source system
What stops one company reading another's dataThe company stamp on every record, and a check that answers unknown rather than passA certification attesting to it
What can it change unattendedNothing that sends, deletes or sharesA guarantee that a reversible action was the right one
Where does the data live, is it used for trainingWritten terms before anything connects: retention, deletion, no third-party trainingA public summary standing in for the terms
What happens on exitThe code, the data and the system handed over, yours to keepAn exit rehearsed before the engagement
04 · What we do not claim

The honest section

01

No certification, of any kind

No SOC 2, no ISO 27001, no HIPAA posture, no badge; if procurement requires one, we cannot pass that gate today.

02

Data terms are agreed per engagement, in writing

Where data sits, who may reach it, how long it is kept, what happens on exit.

03

Anything not measured is named as such

Uptime, latency and accuracy at your scale are absent because nobody has measured them.

Updated 15 September 2026 · WE_AINA

Book a Diagnostic Sprint

See it on your own approvals, with your security lead in the room.

Book a Diagnostic Sprint