Skip to content

Trust

Read-only until trust is old enough to vote.

ALMYSS holds the most sensitive artifact in business life: the inbox of the person in charge. We build as if breach attempts are certain, we show our work on every claim, and the rules we hold ourselves to were written before the first customer.

Needs your approval

Send the reviewed follow-up to Ardent Logistics about invoice 1042.

Nothing is sent until you approve. This lapses after 15 minutes.

What is built, as built.

Read-only by policy

Google is connected with read-only scopes. No write grant to mail exists. Outlook's calendar write scope is granted by the provider but booking is switched off in the product.

Isolation proven, not promised

Every tenant table carries deny-by-default row security. A suite that cannot be skipped tries to read across workspaces with real database sessions on every change.

One permission model

Anything that reaches a customer is proposed on an approval card, re-checked at the moment of acting, limited to owners and admins, and audited. Voice runs through the same gate as typed conversation.

Rate-limited public surfaces

Shared deck links, invitations and every public endpoint are rate-limited per address and per workspace, and a share link can be revoked at any time.

Customer trust principles.

From the ALMYSS Constitution, adopted at the founding so it cannot be mistaken for marketing.

  1. Consent is specific, informed and revocable

    We say exactly what we read, in plain language, before any grant. Disconnection is one click and fully honoured.

  2. The people being read have standing

    Employees whose work flows through ALMYSS deserve transparency about what is derived from it and what their leadership can see.

  3. We surveil no one

    Insight about organisations, never dossiers about individuals. Named-individual analytics do not exist.

  4. We show our work

    Every claim carries sources you can open. Trust built on receipts survives mistakes; trust built on confidence does not.

  5. We admit ignorance

    “I don't know” and “nothing needs you” are commitments, not failures.

  6. Breaches are disclosed, not managed

    If we ever fail our own rules, customers hear it from us first, completely, and fast.

Things ALMYSS will never do.

  • Sell, share or monetise customer data or anything derived from it. Revenue comes from subscriptions, full stop.
  • Train shared or foundation models on one customer's private data for another customer's benefit.
  • Send, modify or delete anything in a customer's systems without an explicit, separate, revocable write grant. None is planned.
  • Build named-individual employee surveillance, productivity scoring or covert monitoring, including for the customer who asks for it.
  • Present an unsourced AI claim as fact.
  • Use dark patterns to acquire, retain or upsell.
  • Let an AI agent take an action a human could not audit, attribute and reverse.
  • Quietly weaken these rules. Amendments are written, argued and signed.

The laws on trust.

Eight of the twenty-five immutable laws of ALMYSS. Numbered because they are numbered in the document they come from.

  1. 16

    Read-only until trust is old enough to vote.

  2. 17

    Isolation is a database guarantee, proven by tests that cannot be skipped.

  3. 18

    Verify at the moment of power; trust nothing cached; every comparison null-safe.

  4. 19

    Ingested content is adversarial; data and instructions never share a channel.

  5. 20

    Secrets and customer content never enter anything observable.

  6. 21

    Insight about organisations, never dossiers about individuals.

  7. 22

    The people being read have standing, not just the person who pays.

  8. 23

    Humans and AI agents act under one permission model, auditable and scoped. No unaccountable actor, silicon or otherwise.

Request access

No certifications are claimed on this page. When one is earned it will be named here with its date.