Supervision and trust

The questions to ask before you put an AI worker on your channels.

We would rather you asked them now. Here is what the platform actually does, and where the binding wording lives.

Your data is never used to train an AI model

What you upload answers your own questions and nothing else. Under the API terms on which we access the AI providers, data submitted through them is not used to train their models, and that sits in our data processing addendum rather than on a policy page you have to take on trust.

Answers are grounded and cited

Workers answer from your own documents first and show which one was used. Where they cannot find it, they say so and hand over instead of inventing an answer.

Every customer reply is fact-checked before it is sent

A second check reads the draft against your company profile, your knowledge base and whatever the worker looked up. A reply that states a price, a policy, a delivery time or a completed action that none of them support is held back, the customer is told your team will come back, and the original is kept in the audit log. This is on by default for every customer-facing worker.

Sign-off where it matters

You choose which actions cannot happen without a person pressing send: quotes, campaigns, public posts, anything that touches money. Every sign-off is logged with who decided and when.

A complete audit trail

Logins, permission changes, agent actions, approvals and data exports are all recorded. When someone asks what happened on a given day, there is an answer.

PDPA rights as a workflow

Access, correction and erasure requests come in through a public form, get identity-verified, and are tracked to completion. Consent is stored in an append-only log, and every campaign carries a working unsubscribe and preference page.

You decide how long data lives

Retention windows for conversations and audit records are set by you, and old data is cleared automatically once they pass.

Access control that survives growth

Per-user permissions, separate roles for admins and staff, optional two-factor authentication on every account, and teams and divisions once the rollout gets larger than one office.

Every worker has a budget

Each worker carries a monthly ceiling and the workspace has a harder one above it. A misconfigured worker or a runaway loop stops at the cap rather than turning into an invoice.

Credentials are encrypted at rest

API keys and channel tokens are stored encrypted, never displayed back in full, and never exposed to the tenants who use the features they power.

No single point of AI failure

Plans can run up to three frontier models in a set order. If one provider degrades, the next takes the request, and higher tiers can cross-check the answer across all of them.

Nobody starts autonomous

Every worker begins in training, answering only to you. You promote it to supervised, and to autonomous later if you ever want to. The state is yours to set and to reverse.

Where processing happens

Built in Singapore, honest about the rest.

The platform is built and operated in Singapore. The AI models behind it are run by a small set of named providers, and some of that processing happens outside Singapore. We do not pretend otherwise. What we do instead is name every sub-processor in our data processing addendum, bind each one to terms that forbid training on your content, and give you the controls above so you can decide what ever reaches them.

If your obligations require processing to stay inside a specific jurisdiction, that is a custom build conversation and we will tell you honestly whether we can meet it.

The documents

These are the binding versions. Anything on this page is a summary of them.

Privacy policy

What we collect, why, and how long we keep it.

Data processing addendum

Our obligations as your data processor, and the sub-processor list.

Terms of service

The commercial agreement, including uptime and liability.

Acceptable use policy

What agents on this platform may not be used for.

Refund policy

Billing, cancellation and refunds.

Data rights request

Ask for a copy of your personal data, or its erasure.

Still have a question your compliance team will ask?

Send it to us before you sign up rather than after. We answer within two business days.