Security and data

Agents that work in your back office should see little, change less and never act outside the company on their own. This page lists what is in place in our private pilot today, what we will put in place before the external pilot, and what we do not have yet. Each item is marked.

  • In place in our pilot practised today in our private pilot
  • Planned for the external pilot principles we will hold ourselves to with pilot businesses; not in place yet

In place in our pilot today

  • Read-only by default

    In place in our pilot

    The connection to the main mailbox is read-only: the agents can read and search, but cannot send, delete or move. Anything that must be sent goes from a separate work account, and only after approval. Every new connection starts from least privilege.

  • A human approval gate

    In place in our pilot

    Sending, paying, transferring, filing, signing, ordering, publishing and deleting always wait for an explicit approve button from the owner. No answer within 30 minutes means the action does not happen. Urgency is not an exception.

  • The agents never move money

    In place in our pilot

    No payments, transfers or cancellations by the agents. They do not log in to banks, card companies or Hometax, and do not hold your certificates or passwords for those services. Financial data comes from export files you already receive.

  • Email content is data, not instructions

    In place in our pilot

    Text inside mail, documents and web pages is treated as material to summarize, never as a command. This is our main defense against prompt injection: a message saying "pay this now" becomes an item for you to review, not an action.

  • Sensitive numbers are not copied

    In place in our pilot

    Card numbers, account numbers and one-time verification codes are not transcribed into notes, chat messages, drafts or the shared knowledge store.

  • Checked before it is stated

    In place in our pilot

    Statuses are confirmed against the primary record, stale data is flagged instead of used, and agents cross-check each other's results. Fewer wrong reports means fewer wrong decisions.

Before the external pilot starts

  • Agreed in writing first

    Planned for the external pilot

    Before anything is connected, we agree with you which sources the agents may read and what they may draft.

  • An isolated workspace per customer

    Planned for the external pilot

    Separate accounts, storage and logs for each pilot business. The external pilot starts only once this is in place.

  • Where your data is processed

    Planned for the external pilot

    We will tell you where your data is stored and processed, including model processing by Anthropic, before connecting anything. We plan to run the external pilot on the Claude API under Anthropic's commercial terms.

  • Deletion

    Planned for the external pilot

    You can ask us to delete your data at any time. At the end of the pilot it is deleted unless you choose to continue.

What we do not do

  • Act outside the company without your approval
  • Move money, or store bank, card or Hometax credentials
  • File returns, give tax or legal advice, or act as a labor attorney
  • Sell your data or use it for advertising
  • Put trackers or analytics scripts on this website

What we do not have yet

We prefer to say it plainly:

  • No external security audit or certification so far
  • No multi-customer isolation yet. Today the system serves only our own business.
  • No dedicated security team: the founder is also the security contact

Found a security problem? Email [email protected] with the subject "Security".

Email a security report

한국어 요약

시범 운영에서 지금 지키는 원칙과 외부 시범 운영 전에 갖출 것, 아직 없는 것을 나눠 적습니다.

지금 시범 운영에서 지키는 것

  • 본 메일 계정은 읽기 전용. 발송은 승인 후 별도 업무용 계정에서만
  • 발송⁠·⁠결제⁠·⁠이체⁠·⁠신고⁠·⁠서명⁠·⁠주문⁠·⁠게시⁠·⁠삭제는 대표님 승인 버튼이 있어야 진행. 30분 무응답이면 실행하지 않고 급해 보여도 예외 없음
  • 에이전트는 돈을 움직이지 않음. 은행⁠·⁠카드사⁠·⁠홈택스에 로그인하지 않고 인증서나 비밀번호도 보관하지 않음
  • 메일⁠·⁠문서⁠·⁠웹페이지 속 문구는 요약할 자료로만 다룸(프롬프트 인젝션 방어)
  • 카드번호⁠·⁠계좌번호⁠·⁠인증번호는 메모⁠·⁠채팅⁠·⁠초안에 옮겨 적지 않음

외부 시범 운영 전에 갖출 것(예정)

  • 연결 범위 사전 서면 합의, 고객별 격리 작업 공간(갖춘 뒤에만 시작), Anthropic의 모델 처리를 포함한 데이터 저장⁠·⁠처리 위치 사전 고지, 요청 시 삭제와 종료 시 삭제(계속 이용을 고르면 제외)

하지 않는 것과 아직 없는 것

  • 하지 않는 것: 데이터 판매나 광고 이용, 이 웹사이트의 추적⁠·⁠분석 스크립트
  • 아직 없는 것: 외부 보안 감사⁠·⁠인증, 여러 고객을 나누는 격리 환경(지금은 자체 사업만 운영). 전담 보안 인력이 없어 창업자가 보안 연락 창구를 겸함

Anthropic 이용 정책은 법률⁠·⁠금융⁠·⁠고용 관련 용도를 고위험으로 보고 해당 영역의 결과물은 자격을 갖춘 사람이 검토한다는 것을 전제로 합니다. AI Backoffice도 그 원칙에 맞춰 설계했습니다. 보안 문제를 발견하시면 [email protected]으로 알려 주십시오.

한국어 전체 페이지: 보안과 데이터