OSAgentOSAgent

Trust

AI should be able to say“I don't know.”

Your company's memory shouldn't become someone else's data.

Those are the two promises this product is built on. The first is about honesty: an answer you cannot check is not an answer, it is a guess with better grammar. The second is about ownership: what OSAgent learns about how your company works belongs to your company, and to nobody else.

Everything below is a behaviour you can verify, not a value we aspire to. Where we fall short of what a security review usually asks for, that is on this page too.

Six things OSAgent does, every time.

Every answer carries its sources

An answer arrives with the messages, pull requests and documents it was drawn from. You can open each one and read the sentence it came from. Provenance is written at the moment a fact is stored, which is the only moment it can be written honestly.

When it can't cite, it refuses

A model asked a question will nearly always produce something. Producing nothing has to be built on purpose. When the record does not support an answer, OSAgent returns the refusal — and tells you which source would need to be connected for the question to be answerable.

One workspace's memory is never another's

Every read is scoped to a workspace and the scope is re-checked on the request, not inferred from a session. Someone who belongs to one workspace and asks for another is refused. There is no shared index across customers.

Read access to your sources

OSAgent requests read scopes and reads your connected sources without modifying your work. It never creates branches, comments on reviews, moves tickets, changes status, or edits or deletes your source data. When delivery is enabled it can send digests and recommendations to destinations your team has explicitly authorized — and nothing else leaves. The blast radius of a mistake on our side is an answer you disagree with, never a change to your tools.

Disconnect removes what that source brought in

Disconnecting is a product feature, not a support request. When a source is disconnected, what it contributed to the memory goes with it — and the answers that depended on it stop being answerable.

You can see what OSAgent has read

Connected sources, when each was last read, and what the memory now contains. The first thing a new workspace sees is what OSAgent is reading — before it answers a single question.

What a refusal looks like.

Every product in this category will show you a confident answer. The demonstration that is hard to copy is the one where nothing comes back.

OSAgent decides after retrieval, not before: if what came back does not anchor to the subject of the question, the answer is the refusal. It is more useful than a fluent paragraph, because it tells you something true about your own record — that the thing you are asking about was never written down anywhere OSAgent can see.

Illustrationa synthetic example, not a customer workspace
osagent · ask

Question

What did we decide about enterprise pricing?

OSAgent

0 sources

Nothing in workspace memory supports an answer here.

Connect the source that would hold it, or ask something the record covers.

For your security reviewer.

The short version, so it can be forwarded without a call. If your reviewer needs detail beyond this, ask us — we would rather answer a hard question early than lose the deal at the last gate.

Encryption
Connector credentials are stored per workspace and encrypted at rest with a key held outside the database. Traffic between your browser, our API and every connected provider runs over TLS.
Role-based access
Five roles — owner, admin, manager, developer, viewer — decide what a member can see and do. Membership of a workspace is the only path to that workspace's data.
Tenant isolation
Workspace scoping is enforced on every query, and membership is re-validated per request rather than trusted from a token issued earlier. A member switching into a workspace they no longer belong to is refused.
Operator boundary
We can provision and suspend workspaces and see operational health and metadata. That console does not read customer content. Access to your memory requires membership of your workspace, like anyone else.
Audit trail
Recommendations record who accepted them and when. Connector changes — connect, reconnect, disconnect — are recorded with the account that made them.
Model use
Your workspace data is not used to train models. Calls to the model provider are metered per workspace, so the cost and the volume of what was processed are both visible to you.

Data handling, retention and deletion are set out in full in the privacy policy.

What we don't claim.

A trust page that only lists strengths is marketing. Here is the other half.

  • No compliance certifications

    We do not hold SOC 2, ISO 27001 or any equivalent, and we have not had a third-party penetration test. If one of those is a hard requirement for you today, we are not the right vendor yet — and we would rather say that now than in week six of procurement.

  • No measured customer results

    No logos, no testimonials, no hours-saved figures, no adoption numbers. We are in a private pilot and we do not have them. When we do have measured results, we will publish how they were measured alongside them.

  • No autonomous execution

    OSAgent does not act on your behalf, write into your tools, or run anything in your infrastructure. Recommendations are proposals until a person accepts them.

  • Extraction quality is still being proven

    Cited retrieval and refusal behave the same way every time. How reliably a decision, an owner or a commitment is extracted from messy real conversation is exactly what the pilot is measuring, and we will tell you where that line currently sits before you connect anything.

Four questions worth asking any vendor in this category.

Including us. If a product cannot answer these in one sentence each, the answers it gives you cannot be checked either.

  1. 1Where did this specific answer come from, and can I open the source?
  2. 2What happens when it doesn't know — does it say so, or does it write something?
  3. 3Whose data is in the same index as mine?
  4. 4What is removed when I disconnect a source, and how would I verify it?
private pilot

Bring your hardest question.

The fastest way to test any of this is to ask OSAgent something it should not be able to answer, and watch what it does.

no self-serve signup · workspaces are set up with you