Is my data safe with an AI assistant? It depends where the AI lives.

With any assistant you can reach from your phone, what you type travels to a computer somewhere — including ours; we will not pretend otherwise. The question that matters is what it lands in when it arrives. With most assistants it lands in a company’s general pool, under terms that can change. With this one it lands in a space of your own: your own encrypted space in our private cloud on Amazon Web Services, scoped to you and nobody else. Joining the service does not change that — the way it is built is the same whether it is your first month or your fifth year. The price is as plain: one bill a year, everything included, and no charge for using it more.

Where does my information actually go?

Into your own encrypted space in our private cloud on Amazon Web Services, in the United States. Every record in it is scoped to you — your files, your messages, the assistant’s memory of them. It is encrypted at rest, with keys held in AWS KMS, and encrypted whenever it moves. And the stores that hold it have no public endpoints: there is no address on the open internet where your archive can be asked for.

What do the AI models see?

Only what a given piece of work needs — the minimum context retrieved for that question. Your assistant reaches the models through Amazon Bedrock, inside the same boundary as everything else, and that traffic travels private networking, never the public internet. Guardrails run on it in addition to our own authorization rules; the credentials that connect your accounts are held in a secrets vault, retrieved just in time, and never shown to the models. What the models see is not used to train them and not shared with the companies that make them.

One boundary. Every honest privacy story comes down to one question: how many places does your material pass through, and who watches each one? Here the answer is one boundary — ours, watched end to end. Your records, the assistant’s thinking and the model traffic all stay inside it, and whatever the assistant does there is logged, so the word private is checkable rather than decorative.

Who else can see it?

No one here is reading your files. There are no ads. Your material is never pooled, never shared, never used to train anyone else’s model, and never sold — ever. Those are written promises, in plain words, on the Trust page.

What can your team see while caring for it?

And what can the assistant itself do without you? It reads what you authorise and drafts on its own. It sends nothing, posts nothing and buys nothing without your yes. It never moves money and never signs anything. The whole table, row by row →

The routine care — updates, checks, backups — runs on service health, never on your documents, mail, or conversations. If a fix ever needs us to see your content, we ask first, in writing, for that one task, and anything we touch comes with a written scope and a written deletion confirmation afterward.

What if something breaks, or the worst day comes?

Backups of your material run continuously and encrypted; restoring them is our job, not yours. You can ask for a complete copy of your material at any time — not only on the way out — and receive it. And when the service ends, your space and everything in it is deleted, confirmed to you in writing.

How do I stay in control day to day?

From your phone or your laptop. You decide what gets loaded, what it connects to, and what it remembers. It asks before it sends or books anything, and it never moves money or signs anything; approvals expire; everything is logged. Answers cite your own records — source, date, location — so you can check them rather than take them on trust. What it learns about you serves you and nobody else, and corrections or deletions of what it remembers are honored, confirmed in writing.

Want to see every promise written down? Read the Trust page. Not sure it fits? Write to us first — if it is not right for you, we will say so in writing. See the price →

Your own encrypted space. Private model traffic. Your yes before anything moves.

$9,995 the first year — everything included. $5,995 each year after. The first year costs more because it contains the preparation — your archive prepared and loaded by hand under a written scope, and your assistant built on it — as well as the first year of the service; every year after is the service running.

Begin the first year — $9,995

Or add the Archive Assessment first — $1,950, credited in full

You order and pay at checkout; we write back within days — a decline returns every dollar, and until our letter confirms the year you may withdraw in writing. From that letter the year is final, and it begins on the date the letter names. Prefer to write to us first?