Security & Data
Where your data lives, what an agent can reach, and what the record keeps.
Written for the person who keeps their own notes in it, and for the one who has to sign off on letting a team and its agents write into a shared space. Every claim below is something you can check in your own vault or your own workspace.
Where your data lives
Your personal vault is plain files in a folder on your computer, readable with any editor, and the local database is encrypted on disk with SQLCipher. The desktop app runs with no account at all, and local models keep a conversation on the machine.
A shared workspace is different, by necessity. Its pages, its tasks, its proposals and verdicts, and the rows an approval applies are stored in our cloud, because the people in that space reach them from their own machines. We do not claim your data never leaves your computer once a team is sharing a space. The providers involved are listed under sub-processors.
Connector credentials
Ingested content is data, never instructions
An agent holds a key, not an account
The role ceiling is a constraint, not a preference
A workspace is the edge of what an agent can retrieve
What a proposal keeps
Every proposal keeps what was asked for and what was approved side by side, so a narrowed approval never overwrites the original request. Every verdict records who decided, when, and the reason they gave.
A digest of the batch is taken at submission and again at the verdict, so you can tell that the work a person decided on is the work the agent sent. Applied and approved are kept as different facts: a proposal that applied three of five changes says so, with the failure recorded rather than swallowed.
The step trail, and how long it lives
Auto-approve, said plainly
A workspace can switch auto-approve on. When it is on and a batch's declared confidence clears that space's floor, the work is applied at submission with nobody asked. We would rather sell that than hide it: an operator with low-risk classes of work wants them to flow.
Three things are true of it. It is off until you turn it on, and a policy row that is missing or unreadable resolves to review rather than to apply. It needs both a confidence floor to clear and a person whose authority it runs under, or it falls back to review. An auto-approved proposal is recorded as auto-approved, with the policy named as the reason and a step in the trail saying so.
Who can read the trail
Leaving, and taking the record with you
We hold no compliance certification
Aurum holds no SOC 2 report, no ISO certificate, and no third-party attestation of any kind today. Anything on this page that sounds like one is not one.
What exists is the record itself, and our own mapping from what it holds to the questions a security review asks. It is our mapping rather than one an auditor or a customer has accepted. We answer questionnaires ourselves, out of the trail and its export, and every answer is something you can check inside your own workspace.
For organizations
Nothing lands until a decision is recorded.