Trust and security

Local-first by default. Honest about the rest.

Automateagile keeps your work in your browser, with no account and no server. The only thing that ever leaves your machine is what you choose to send to your own AI endpoint, and you can turn that off entirely. Below is what is shipped today and what is on the roadmap, with no fudging between the two.

No account
Nothing to sign up for. Shipped.
No server
Your data stays in the browser. Shipped.
No tracking
No cookies, no analytics. Shipped.
Bring your own key
AI uses your own endpoint. Shipped.
Wipe any time
You own and can delete it all. Shipped.
DPA on request
For the paid tier. Roadmap.
SSO and audit trail
For the governed tier. Roadmap.

Local-first by default

Shipped today

Everything lives in your browser. There is no account, no server, and nothing is transmitted unless you turn on AI sparring. Open the companion, name your space, and start. Your roadmap, your situation notes, and your decision records are kept in this browser's local storage, on this device.

Because there is no account, there is also no password to leak and no central database to breach. The flip side is honest too: if you clear this browser's storage without exporting first, the data is gone, the same way a local file would be. The encrypted export, below, is how you keep a durable copy and move between machines.

What leaves your machine

Shipped today

One thing, and only when you ask for it. When you use AI sparring, three things go to the endpoint you choose:

You decide how much of that moves, and where it goes:

Structure-only or redacted

Send the shape of the situation without the sensitive detail. Strip names and specifics, keep the pattern.

Your own org gateway

Point it at your company's approved AI gateway so calls stay inside your compliance boundary.

AI off entirely

Turn AI sparring off and nothing leaves your machine at all. The full method still works.

There is no Automateagile server in the path. The call goes from your browser to your chosen endpoint, with your key. We never see your prompt, your context, or your key.

Data residency and your control

Shipped today

You own your data and the place it lives. Concretely:

For the AI path, residency is your choice: point sparring at an endpoint in the region you need, or at your own org gateway, and the data that moves stays where you sent it.

A DPA for the paid tier

Roadmap, on request

A Data Processing Agreement is available on request for the paid tier. If your organisation needs a signed DPA before a Lead Seat, Team or Enterprise plan, ask when you request your seat and it will be part of the conversation. Today this is handled per request rather than as a self-serve download, and that is the honest state of it.

SSO and an audit trail

Roadmap, governed tier

Single sign-on through your own identity provider and a tamper-evident audit trail of who changed what are planned for the governed tier, alongside Enterprise onboarding. They are not shipped yet. If you need them, say so when you request a seat and we will be straight with you about timing rather than promising a date the build cannot back.

No tracking, no cookies, no analytics

Shipped today

The site and the companion carry no third-party trackers, no advertising pixels, and no analytics. Nothing follows you between pages, and nothing is profiled.

No tracking
No cookies
No analytics

Honest about today versus the roadmap. Everything tagged "Shipped today" works right now. Everything tagged "Roadmap" is planned and not yet built, including the DPA as a standard document, SSO, and the audit trail. We would rather under-promise here than have you discover the gap after you buy. If a control you need is on the roadmap, ask, and we will tell you where it really stands.