An assistant with access to your working life
is a position of trust.
The more an assistant can actually do, the more that trust matters. One action you didn't authorise resets it to zero. So here is how we bound what ours can do — in plain language, and limited to things that are true today.
Your assistant is fully AI. No person does your work.
Nobody is working through your requests by hand on the other end. The work is done by software, which is what makes it available at three in the morning and what makes it affordable. That is what we mean when we say 100% AI — not that nobody is checking it. You are.
You approve what goes out, and you see it first.
Consequential actions are staged for review rather than fired as they are composed. You see the actual message — the real recipients, the real text — before anything is sent, and you can edit it, remove one item, or reject the lot.
After you approve, nothing rewrites your words.
Once you approve a message, no AI model runs between that approval and the send. The words that go out are the words you read. The system will attach your signature, thread the message onto the right conversation, and honour your own supervision settings — which can mean adding someone you asked to be kept in the loop — but nothing reinterprets what you wrote. This is a property of how the system is built, not a policy we promise to follow.
The assistant cannot quietly widen its own remit.
Every outbound action travels the same path, and that path is where your settings decide whether it goes straight out or waits for you. There is no second route around it — the ability to send directly does not exist. It cannot approve its own work. And it cannot loosen the level of oversight it operates under: it can tighten its own supervision, but no instruction, however cleverly worded and wherever it arrives from, can talk it into loosening it — that direction is blocked, not merely discouraged.
You decide how much runs unattended.
Autonomy is set per category of action, by you. Some things you will want done without being asked. Others you will always want to see. Both are settings, not defaults you have to live with — and you can change your mind at any point.
Your organisation's administrators have real controls.
An IT administrator can switch a connected service off for the whole organisation and lock that choice so an individual cannot undo it, and can permit or block individual third-party tools. These are settings your administrator holds, not a request form they have to send us.
We ask for the narrowest access that works.
When you connect a service, we request the permissions that connection actually needs rather than the widest set the provider would grant us. And when someone's role changes, their assistant's access to them ends across every channel at once.
We don't train on your data. Neither do our providers.
Not our models, not anyone else's. Our AI providers are contractually prohibited from training on customer data. This is in our contract with you, not only on a webpage — a webpage can be edited on a Tuesday afternoon.
Inside the system, everything is on a need-to-know basis.
Your data is isolated from every other customer's, and we run a continuous programme specifically to verify that boundary holds. The same principle applies between the parts of your own assistant: when it negotiates a meeting time, that process works from availability alone — not the titles of your meetings or who is in them.
We check what arrives before it reaches your assistant.
Inbound email has to prove it is genuinely from who it claims before your assistant ever sees it; forgeries are rejected at the door. Requests that look unusual for the person making them are held and referred to you rather than acted on. We will not tell you we are immune to manipulation — nobody honest will. We will tell you what we check and what happens when a check fires.
One switch stops everything.
If something looks wrong, an account-wide stop halts every pending and in-flight action immediately. Only you can lift it from your own account — your assistant cannot lift it, and neither can anyone talking to your assistant.
Leaving is a real option.
Disconnect a service and we stop using it. Delete your account and we begin deleting your data. Some of it lives in threads other people are part of, so what we remove and what we keep in anonymised form is set out precisely in our Privacy Policy rather than summarised as a slogan here.
Things we do not do
- We never take a perpetual or irrevocable licence to your content or your outputs. You own what you put in and what comes out.
- We never appoint ourselves your agent. Your assistant acts within the scope you configure or approve, and nothing it does creates a commitment you did not authorise — which is why the record of what you approved matters.
- We do not sell your data, and data from the services you connect is never used for advertising.
Independently verified: SOC 2 Type II, audited annually by an independent CPA firm. GDPR and CCPA compliant. Third-party penetration testing every year, with the summary available to customers under NDA.
The full detail — certifications, controls, subprocessors, and policy documents — is in the Trust Center. Questions, or reporting a vulnerability? security@openassistant.us, monitored by our security team. Our disclosure policy, including safe harbour for good-faith research, is on the Trust Center.