The Brain / Security
It acts only as the person who signed in.
Nothing in a document, an email, or the AI's own output can change who that is, or approve an action on their behalf.
A hidden instruction cannot change who is asking
The attack that matters is a sentence hidden in a document that talks the AI into naming a different company or user; the proof page holds what is not proven.
Who it acts as comes from the sign-in
The person, the company and every credential are taken from the signed-in session, and stripped from whatever the AI writes.
It cannot approve its own action
A yes only counts when a person clicked it; an approval written by the AI is not one.
Credentials are read at the moment of use
Never cached at start, so a revoked credential takes effect at the next call, not the next restart.
What it may read, and what it may change on its own
Reads stay inside your company's own data
Every record and remembered fact is stamped with the company it belongs to, and a read stays inside that stamp.
An uncheckable stamp answers unknown, never pass
No query runs without it.
71 of 287 actions stop for a person
Everything that sends, deletes or shares, by category, so a new action of that kind stops from the day it exists.
What it says is checked against what happened
It checks the change landed before telling you, and its reply against what the tools returned.
The five questions a review asks
| The question | What we can show | What we cannot |
|---|---|---|
| Who is the system acting as | The person who signed in, with identity stripped from the AI's output first | A per-user mirror of the permissions in your source system |
| What stops one company reading another's data | The company stamp on every record, and a check that answers unknown rather than pass | A certification attesting to it |
| What can it change unattended | Nothing that sends, deletes or shares | A guarantee that a reversible action was the right one |
| Where does the data live, is it used for training | Written terms before anything connects: retention, deletion, no third-party training | A public summary standing in for the terms |
| What happens on exit | The code, the data and the system handed over, yours to keep | An exit rehearsed before the engagement |
The honest section
No certification, of any kind
No SOC 2, no ISO 27001, no HIPAA posture, no badge; if procurement requires one, we cannot pass that gate today.
Data terms are agreed per engagement, in writing
Where data sits, who may reach it, how long it is kept, what happens on exit.
Anything not measured is named as such
Uptime, latency and accuracy at your scale are absent because nobody has measured them.
Updated 15 September 2026 · WE_AINA
Book a Diagnostic Sprint
See it on your own approvals, with your security lead in the room.