Built like something you would let near your business
The short version: raw content is processed and dropped, every action is on a permission ladder with an immutable audit trail, and nothing about this page is marketing-only. Each claim is product behavior.
| Claim | Mechanism | Where to verify |
|---|---|---|
| Raw Slack content never persists | Messages are read in flight; the pipeline drops raw content after distillation, keeping only the distilled item with provenance | Privacy policy and DPA |
| No irreversible action without approval | Action levels per tool operation; irreversible operations park an approval request with the arguments frozen and digest-verified | The audit trail in the app |
| Every employee action is logged | Append-only audit events with actor, level, and input digest | Audit export in the app (12-month retention) |
| Your keys, your data agreement | BYOK routes model calls through your own provider account; the default gateway runs no-training configurations | Workspace model settings |
| Employees always disclose they are AI | In the profile, on first contact, and whenever asked; product behavior, not a setting | Any employee profile |
| Encrypted everywhere, credentials vaulted | TLS in transit, encryption at rest, third-party credentials in a server-side vault injected server-side only | The subprocessor list |
Employees read messages in flight, distill knowledge worth keeping (with provenance), and drop the raw content. Pagerox never holds a mirror of your message history.
Which channels each employee listens to is visible to the whole workspace, every channel can opt out, and ambient listening is off by default.
Every tool operation an employee can touch carries an action level: observe, notify, suggest, or act. Anything irreversible parks an approval request a manager decides with the exact arguments frozen and digest-verified.
Autonomy is earned: levels move up through explicit manager grants, or, when a manager raises the self-evolution dial, through the employee's own improvement loop. Even then every change is versioned, lands as an FYI, is one-click revertible, and can never come from ingested content.
The self-evolution dial (L0 proposals-only by default) is manager-set and never self-modifiable. Neither are credentials, connections, spend caps, or the kill switch. Three reverted self-changes in 30 days drop the dial automatically.
Every action an employee takes is logged append-only with actor, level, and an input digest (not the raw arguments). Audit logs are retained for 12 months on standard plans and are exportable.
Model calls route through the Vercel AI Gateway under no-training configurations. Bring your own OpenAI, Anthropic, or Google keys and inherit your own data agreement with the provider; model costs pass through at provider rates.
Employees always identify as AI: in their profile, on first contact, and whenever asked. This is product behavior, not a setting.
Data is encrypted in transit (TLS) and at rest by our infrastructure providers. Third-party credentials employees use live in a server-side vault, are injected server-side only, and never appear in the database, logs, or the browser.
SOC 2 Type I is initiated at launch. This page, the data flows on it, and the subprocessor list are public from day one.
Who touches your data: the subprocessor list. The paper kit: Terms, Privacy, DPA, AUP.