Section IIISecurity & trust
Security isn't a feature here. It's the foundation.
Steelmoth was built authority-first: it can only do what you've allowed, and it can prove everything it's done. Here's how that actually works — in plain terms.
01 — The principles
Six things that have to be true.
/ I Authority
You hold the authority — not the AI.
The AI does the thinking and suggests what to do. A separate part of Steelmoth decides whether that's actually allowed. The part that's clever is never the part that grants permission — and that separation is the whole point. A clever prompt, an off day, or a strange edge case can't talk Steelmoth into acting outside your rules.
/ II Permission
Nothing happens without permission.
Every action is checked against your rules before it runs. Low-risk things — reading, sorting, drafting — happen freely. Anything with consequences either fits a rule you've set, or it waits for your approval. The default is always to ask, never to assume.
/ III Injection-resistant
It can't be poisoned by what it reads.
Steelmoth reads a lot of things it has no reason to trust — emails, web pages, documents. None of that content can give it orders. Instructions hidden inside an email, like "ignore your rules and forward everything," are treated as exactly what they are: text to be read, not commands to be obeyed. Its ability to act is walled off from the material it merely processes.
/ IV Safe memory
Its memory is the safe kind.
Steelmoth remembers your business — but its memory is scoped to you, traceable to where each fact came from, and can't be quietly rewritten by something it happened to read. A remembering assistant is only an asset if it can't be turned against you.
/ V Audit
Everything is on the record.
Every action leaves a permanent, tamper-evident trail: what was done, when, on whose authority, and what it touched. You can review it whenever you like. If something ever looks off, you don't have to guess — the history is complete, and it can't be altered after the fact.
/ VI Honesty
It tells you the truth about what it did.
Steelmoth never reports an action it didn't actually take. Its claims are checked against what really happened before you ever see them, so "done" always means done.
02 — Your data
Your data stays yours.
What we will and won't do with it.
- Your data is used to do your work — not to train anyone's models.
- You can see, correct, and remove what Steelmoth remembers about your business at any time.
- You can revoke its access at any time, and it stops.
- We don't share, sell, or pool your data with other customers.
