Safe AI automation, on your computer

Everyone tells AI to think outside inside the box.

An AI assistant that can plan anything — and touch nothing — until you approve. It drafts. You decide. The box does exactly what you signed off on, and writes every step to a record no one can quietly edit. Not even us.

Join the early-access list See how the box works
Inside the box · nothing runs without you
AI
I can clean up your Downloads folder. Here's my exact plan — nothing has happened yet:
1. MOVE 214 screenshots → Pictures/Screenshots
2. MOVE 38 PDFs → Documents/Receipts
3. DELETE nothing. Ever, without asking.
✓ Approve & signEdit planCancel
You
Approved. ✓
ledger #4,182 · plan signed by you · executed in sandbox · 252 files moved, 0 deleted · record sealed ✓
How it works

The AI proposes. You dispose. The box obeys — exactly.

Most AI agents ask you to trust them with the keys. Ours is built so it never holds the keys at all. Three steps, every single time:

01 — DRAFT

The AI writes a plan, not an action

Whatever you ask for, the AI produces an inert, readable plan — plain steps you can inspect. The drafting engine is physically incapable of touching your files, your accounts, or the internet. It can only write.

02 — SIGN

You approve with your signature

Nothing proceeds without your cryptographic approval — one tap that only your device can produce. No approval, no action. There is no override, no "just this once," no fine print.

03 — EXECUTE & RECORD

A dumb, obedient machine runs it

A separate executor — deliberately boring, with no creativity at all — runs your approved plan step for step in a sealed sandbox, then writes every action to a tamper-evident ledger you can audit forever.

The five promises

Guarantees built into the architecture — not the terms of service.

Every promise below is enforced by how the software is physically constructed, and verified by tests that run on every release. If a promise fails, the product doesn't ship.

It can't act alone

The creative AI is sealed off from your files, your network, and your accounts. It drafts plans; it cannot execute even one step of them.

// synthesis engine: no exec, no network — verified structurally

Nothing is hidden

Every plan is shown to you in plain language before anything happens. No background actions, no silent retries, no surprises.

// plans are inert, human-readable data

Your signature is the only key

Actions run only after approval that's cryptographically yours. Lose the signature, and the box simply stays shut.

// Ed25519 signed approvals, per plan

Same plan, same result

The executor is deterministic — it does exactly what the approved plan says, the same way every time. No improvisation between your yes and the result.

// deterministic, sandboxed executor

Everything on the record

Every event is written to an append-only, tamper-evident ledger. Anyone changing history breaks the seal — visibly.

// hash-chained audit ledger
"We didn't teach an AI to behave.
We built a box where misbehaving is impossible."
Early access

Put your computer in good hands. Yours.

We're onboarding a small group of early users who want AI automation without the leap of faith. On your machine, under your signature, on the record.

CONCEPT MOCKUP