Everything an agent is allowed to do
is written down, by name.

None of this rests on an agent behaving well. It runs on a server that is yours, on keys that are yours, and the only actions it can take are the ones standing in a file you can read.

Last reviewed 26 August 2026

Two columns, one deal.
We harden it, you decide.

AI safety is not something we hand you finished. We harden the machine and the gate; you decide what the agent may touch. Both halves are written down, and both halves are checkable.

We ensure
  • A gate that refuses by default. Every action passes one function; anything that means change or send is refused unless it stands on the list by name.
  • A hardened machine. Keys only, firewall with three open ports, automatic security updates, encrypted traffic, repeated logins banned at the door.
  • Nothing shared. Your instance runs your business and no one else's — no pool, no shared queue.
  • A checkable trail. Whatever an agent said or did, the input that produced it is on the machine you own.
You define
  • What it may do, per action. The permission list is written per agent, reviewed with you, and kept under version control.
  • Where autonomy switches on. Categories go autonomous one by one, on numbers you can see — and back off in one action.
  • The limits that hold. Refund ceilings, subjects that stay yours permanently, when a thread must come to you — your rules, in the file.
  • The access itself. Granted from your own accounts, withdrawn the same way — your mailbox and shop stay yours to disconnect.

Every action passes one function.
And it refuses by default.

The gate reads the tool's own name. A name built on get, list, search, fetch or query reads, so it goes through. A name carrying one of twenty-eight words that mean change or send is refused. Anything the gate cannot place is refused too — that is the default, not the exception.

Action requested Gate What happens
shopify.get_order
Passed reads only — get
gmail.send_message
Refused send is one of the twenty-eight
shopify.list_products
Passed reads only — list
gmail.delete_message
Refused delete is one of the twenty-eight
tracking.fetch_status
Passed reads only — fetch
shopify.create_refund
Refused create and refund, both on the list
composio.execute_tool
Refused generic pass-through: the real action hides in the input, so the name says nothing the gate can check
gmail.create_draft
Passed create and draft are both on the refuse list — it runs only because a person put this one name in the file
Anything else
The gate has no third answer. A name it cannot place is refused, on the days that is inconvenient too.

Reads — goes through

getlist searchfetch query

A name has to carry one of these and none of the twenty-eight.

Means change or send — refused unless named in the file

createupdate deleteremove mutationsend publishapply activatecancel refundbulk deployupload generateclone writeedit setswitch labeldraft importmove duplicaterename connectdisconnect

label and draft stand on this list, which is why the two actions the mail agent lives on had to be written down by name before they could run at all.

Permission is a list.
And a person wrote it.

This is the mail agent's actual permission file during its learning period. Two actions may change something, both written out by name. Sending is not among them, so it cannot happen — not because the agent was told to behave, but because the name is not in the file.

tools.json agents/klantenservice-agent/
{  "gmail": [    "GMAIL_FETCH_EMAILS",              // reads    "GMAIL_FETCH_MESSAGE_BY_MESSAGE_ID", // reads    "GMAIL_LIST_LABELS",              // reads    "GMAIL_ADD_LABEL_TO_EMAIL",       // changes something    "GMAIL_CREATE_EMAIL_DRAFT"         // changes something  ],   // The gate refuses every name above that changes or sends.  // These two run only because they stand here, by name:  "allowed_mutations": {    "gmail": [      "GMAIL_CREATE_EMAIL_DRAFT",   // write a reply as a draft      "GMAIL_ADD_LABEL_TO_EMAIL"     // put a label on a message    ]  }   // Not here, and therefore refused before it runs:  //   GMAIL_SEND_EMAIL      — sending anything at all  //   GMAIL_DELETE_MESSAGE  — deleting or changing a message  //   everything else in the mailbox}

Your own machine.
An agent that knows only what it was handed.

The build runs on its own instance, rented in your name, in a European data centre. Nothing else runs on it. Inside, the agent starts with inherited context switched off: what it knows arrives in four files and nothing else.

YOUR INSTANCE Hetzner, European data centre — the ISO/IEC 27001 certificate is theirs, not ours.
LoginKeys only. Password logins off.
FirewallThree ports open, nothing else reachable.
UpdatesSecurity updates install automatically.
fail2banRepeated logins banned at the door.
TrafficEncrypted on anything leaving the machine.
The agent inherited context: off

It picks up no house instructions and no settings lying around in the environment — the runtime runs on settingSources: []. Four files, handed over explicitly:

spec.mdIts own instructions — what this role does.
brand.jsonYour business profile: wording, windows, policies.
tools.jsonWhich tools it may reach, and what it may change.
skills.jsonWhich skills it may see.

Nothing else comes with it. No shared prompt, no settings from our machines, no other business's file within reach.

Another customer's instance Own machine, own keys, own configuration file.
no connection
Any shared pool or queue Does not exist here. Nothing is pooled, nothing averaged across clients.

The engine is the same for everyone; the fuel is yours. That is what makes the work portable — and what keeps one customer's configuration out of reach of every other machine.

Who else sees anything.
Four parties, the whole list.

Four parties, and that is the whole list:

Anthropic
Runs the model that does the thinking. Sees the configuration and whatever the agent reads during a run. Does not train on it: that is their own policy for paid API use, published on anthropic.com.
Composio
Brokers the connections to Shopify, Klaviyo and Gmail, and holds the access you granted through your own login. Sees what an agent requests while a run is happening. We name it here because it is a real party between you and your own systems.
Hetzner
Hosts the machine. Sees what any host sees: the files and logs standing on it. The infrastructure holds ISO/IEC 27001:2022 (checked on their certification page, 13 August 2026) — the certificate is theirs, not ours, and we say so below.
The tools you already use
Shopify, Klaviyo, Gmail and the rest. Your data was already there. An agent reads it with access you issued and can withdraw.

The intake form on this site is a separate matter with its own answer, and it is on the privacy page.

What we do not claim.
The gaps belong on this page too.

A security page is worth reading only if the gaps are on it too:

On paper, before anything is connected.
Signed before a single account is linked.

A data processing agreement is signed before a single account is linked. The access list per agent is part of it: what it may read, the actions it may take by name, and what it can never do. If that list ever needs to grow, it grows the same way it was written — you see it, you agree to it, and it goes into version control.

Access is granted by you, from your own accounts, and withdrawn the same way. Your mailbox and your shop stay connected on permissions you issue and can pull back, which is what makes that sentence true rather than kind.

Every week you wait,the competition pulls further ahead.

Seth Desaunois Book your audit call30 minutes

No sales pitch. The person who builds it, running the numbers on your operation.