Trust is the product

A system with this much context about a person is only worth building if the controls come first. Here is exactly how they work.

Baseline

From the first install

Encrypted at rest and in transit

Your memory, documents and transcripts are encrypted on the Core. Losing the machine does not mean losing control of what's on it.

Least-privilege access

Every integration is connected with the narrowest scope that does the job. Alfred never asks for, and never holds, unrestricted credentials to your accounts.

Tamper-evident ledger

Every consequential action Alfred takes is written to an append-only record you can review line by line — what was done, when, on whose authority, and why.

Source attribution

Answers carry their evidence. If Alfred says you agreed something, it shows you the message, document or transcript where you agreed it.

Read-only first

Onboarding connects everything read-only and starts in observe mode. Authority is granted in stages, by you, and can be withdrawn the same way.

Your data is never the product

No advertising, no data sale, no training a general model on your life. The business model is a subscription, deliberately.

The boundary

What leaves the box, and when

In the default Private Hybrid deployment, routine work — classification, extraction, transcription — happens locally. Heavier reasoning may be routed to an approved external model, and you control that switch.

WorkPrivate LocalPrivate Hybrid
Memory graph & document vaultOn your CoreOn your Core
Classification & extractionLocalLocal
TranscriptionLocalLocal
Heavy reasoning & long-form draftingLocal modelApproved external model
Audit ledgerOn your CoreOn your Core
Data used to train anyone's modelNeverNever

Exact behaviour is documented per integration before it is enabled, and every routed request is written to the ledger.

Your rights

Leaving is a supported action

Export everything

Your memory, documents and ledger export in open formats. No hostage-taking of the thing that makes Alfred valuable.

Delete for real

Deletion removes the data and is recorded as an action, so you can see it happened.

Revoke instantly

Any integration or autonomy mode can be pulled back to observe-only at any moment, without support tickets.

Note: this page describes the designed security and privacy model of a product in development. It is not a legal commitment or a certification claim. Formal terms, data-processing documentation and the published privacy policy will accompany the first paid installs — see our current privacy policy for how this website itself handles data.

Questions before you'd trust it?

That's the right instinct. Ask them directly — vague answers about security are a bad sign in any product.