Security
Hand it the real work. That means trusting it first.
Local execution
Runs on your own device with files you already have. Nothing is sent elsewhere just to get the work done.
Controlled sandbox
Steps that take action run inside a controlled sandbox, isolated from the rest of your system.
Narrow, auditable egress
Outbound network access goes through a narrow, controlled egress that is observable and auditable.
Asks before the irreversible
Deleting, sending, publishing, or paying: anything you cannot take back requires your go-ahead first. What it did and which files it changed remain visible and reversible.
It completes tasks, but consequential decisions remain with you.
Read the System Card