Security and data
Agents that work in your back office should see little, change less and never act outside the company on their own. This page lists what is in place in our private pilot today, what we will put in place before the external pilot, and what we do not have yet. Each item is marked.
- In place in our pilot practised today in our private pilot
- Planned for the external pilot principles we will hold ourselves to with pilot businesses; not in place yet
In place in our pilot today
-
Read-only by default
In place in our pilotThe connection to the main mailbox is read-only: the agents can read and search, but cannot send, delete or move. Anything that must be sent goes from a separate work account, and only after approval. Every new connection starts from least privilege.
-
A human approval gate
In place in our pilotSending, paying, transferring, filing, signing, ordering, publishing and deleting always wait for an explicit approve button from the owner. No answer within 30 minutes means the action does not happen. Urgency is not an exception.
-
The agents never move money
In place in our pilotNo payments, transfers or cancellations by the agents. They do not log in to banks, card companies or Hometax, and do not hold your certificates or passwords for those services. Financial data comes from export files you already receive.
-
Email content is data, not instructions
In place in our pilotText inside mail, documents and web pages is treated as material to summarize, never as a command. This is our main defense against prompt injection: a message saying "pay this now" becomes an item for you to review, not an action.
-
Sensitive numbers are not copied
In place in our pilotCard numbers, account numbers and one-time verification codes are not transcribed into notes, chat messages, drafts or the shared knowledge store.
-
Checked before it is stated
In place in our pilotStatuses are confirmed against the primary record, stale data is flagged instead of used, and agents cross-check each other's results. Fewer wrong reports means fewer wrong decisions.
Before the external pilot starts
-
Agreed in writing first
Planned for the external pilotBefore anything is connected, we agree with you which sources the agents may read and what they may draft.
-
An isolated workspace per customer
Planned for the external pilotSeparate accounts, storage and logs for each pilot business. The external pilot starts only once this is in place.
-
Where your data is processed
Planned for the external pilotWe will tell you where your data is stored and processed, including model processing by Anthropic, before connecting anything. We plan to run the external pilot on the Claude API under Anthropic's commercial terms.
-
Deletion
Planned for the external pilotYou can ask us to delete your data at any time. At the end of the pilot it is deleted unless you choose to continue.
What we do not do
- Act outside the company without your approval
- Move money, or store bank, card or Hometax credentials
- File returns, give tax or legal advice, or act as a labor attorney
- Sell your data or use it for advertising
- Put trackers or analytics scripts on this website
What we do not have yet
We prefer to say it plainly:
- No external security audit or certification so far
- No multi-customer isolation yet. Today the system serves only our own business.
- No dedicated security team: the founder is also the security contact
Found a security problem? Email [email protected] with the subject "Security".
한국어 요약
시범 운영에서 지금 지키는 원칙과 외부 시범 운영 전에 갖출 것, 아직 없는 것을 나눠 적습니다.
지금 시범 운영에서 지키는 것
- 본 메일 계정은 읽기 전용. 발송은 승인 후 별도 업무용 계정에서만
- 발송·결제·이체·신고·서명·주문·게시·삭제는 대표님 승인 버튼이 있어야 진행. 30분 무응답이면 실행하지 않고 급해 보여도 예외 없음
- 에이전트는 돈을 움직이지 않음. 은행·카드사·홈택스에 로그인하지 않고 인증서나 비밀번호도 보관하지 않음
- 메일·문서·웹페이지 속 문구는 요약할 자료로만 다룸(프롬프트 인젝션 방어)
- 카드번호·계좌번호·인증번호는 메모·채팅·초안에 옮겨 적지 않음
외부 시범 운영 전에 갖출 것(예정)
- 연결 범위 사전 서면 합의, 고객별 격리 작업 공간(갖춘 뒤에만 시작), Anthropic의 모델 처리를 포함한 데이터 저장·처리 위치 사전 고지, 요청 시 삭제와 종료 시 삭제(계속 이용을 고르면 제외)
하지 않는 것과 아직 없는 것
- 하지 않는 것: 데이터 판매나 광고 이용, 이 웹사이트의 추적·분석 스크립트
- 아직 없는 것: 외부 보안 감사·인증, 여러 고객을 나누는 격리 환경(지금은 자체 사업만 운영). 전담 보안 인력이 없어 창업자가 보안 연락 창구를 겸함
Anthropic 이용 정책은 법률·금융·고용 관련 용도를 고위험으로 보고 해당 영역의 결과물은 자격을 갖춘 사람이 검토한다는 것을 전제로 합니다. AI Backoffice도 그 원칙에 맞춰 설계했습니다. 보안 문제를 발견하시면 [email protected]으로 알려 주십시오.