Built like something you would let near your business

The short version: raw content is processed and dropped, every action is on a permission ladder with an immutable audit trail, and nothing about this page is marketing-only. Each claim is product behavior.

Security claims, the mechanism behind each, and where to verify them
ClaimMechanismWhere to verify
Raw Slack content never persistsMessages are read in flight; the pipeline drops raw content after distillation, keeping only the distilled item with provenancePrivacy policy and DPA
No irreversible action without approvalAction levels per tool operation; irreversible operations park an approval request with the arguments frozen and digest-verifiedThe audit trail in the app
Every employee action is loggedAppend-only audit events with actor, level, and input digestAudit export in the app (12-month retention)
Your keys, your data agreementBYOK routes model calls through your own provider account; the default gateway runs no-training configurationsWorkspace model settings
Employees always disclose they are AIIn the profile, on first contact, and whenever asked; product behavior, not a settingAny employee profile
Encrypted everywhere, credentials vaultedTLS in transit, encryption at rest, third-party credentials in a server-side vault injected server-side onlyThe subprocessor list
Slack: processed, not stored

Employees read messages in flight, distill knowledge worth keeping (with provenance), and drop the raw content. Pagerox never holds a mirror of your message history.

Which channels each employee listens to is visible to the whole workspace, every channel can opt out, and ambient listening is off by default.

Permissions: a ladder, not a switch

Every tool operation an employee can touch carries an action level: observe, notify, suggest, or act. Anything irreversible parks an approval request a manager decides with the exact arguments frozen and digest-verified.

Autonomy is earned: levels move up through explicit manager grants, or, when a manager raises the self-evolution dial, through the employee's own improvement loop. Even then every change is versioned, lands as an FYI, is one-click revertible, and can never come from ingested content.

The self-evolution dial (L0 proposals-only by default) is manager-set and never self-modifiable. Neither are credentials, connections, spend caps, or the kill switch. Three reverted self-changes in 30 days drop the dial automatically.

Audit: immutable and exportable

Every action an employee takes is logged append-only with actor, level, and an input digest (not the raw arguments). Audit logs are retained for 12 months on standard plans and are exportable.

Models and your data

Model calls route through the Vercel AI Gateway under no-training configurations. Bring your own OpenAI, Anthropic, or Google keys and inherit your own data agreement with the provider; model costs pass through at provider rates.

AI disclosure

Employees always identify as AI: in their profile, on first contact, and whenever asked. This is product behavior, not a setting.

Encryption and infrastructure

Data is encrypted in transit (TLS) and at rest by our infrastructure providers. Third-party credentials employees use live in a server-side vault, are injected server-side only, and never appear in the database, logs, or the browser.

SOC 2 Type I is initiated at launch. This page, the data flows on it, and the subprocessor list are public from day one.

Who touches your data: the subprocessor list. The paper kit: Terms, Privacy, DPA, AUP.