Security

Start with what it cannot do.

Roy reads the most sensitive picture of you that exists. So the useful thing to state first is not what it can do, but what it is structurally unable to do.

Cannot sendno mail, message, post or reply leaves without your approval
Cannot spendno payment, order or trade is placed on its own
Cannot unlocklocks, garage and alarm are always a separate yes
Cannot touch the never-touch listthreads you mark private are excluded, not merely unsurfaced
Cannot train anyone's modelyour content is never used to train a model, ours or a provider's
Cannot be reached from the internetit binds to localhost; there is no public port

Your data is not training anyone's model.

Roy runs on your own API keys. Your mail, notes and deals go from your machine to the model provider you chose, under your account and their terms, and come back. We are not in that path and we do not keep a copy. No telemetry carries your content, and there is no corpus being assembled out of your inbox.

The business model is the licence. It is not your data, which is the only version of this promise that survives a funding round.

Your keysyour provider account, your terms
No copywe never receive your content
No corpusnothing retained to train on

The never-touch list.

Some threads are nobody's business but yours, and "the agent decided not to surface it" is not good enough.

Excluded

Named senders and threads

Mark a person, a domain or a thread and it is dropped before judgement, not filtered after it. Nothing about it reaches a draft, a brief or a summary.

Read-only

Family and confidential mail

Read so the rest of your day makes sense, never drafted against. Roy will not write a reply to your family or your lawyer, whatever you ask it.

Separate

The health vault

Health lives in its own store. It is summarized into your week and never exposed to the rest of the agent or to any other surface.

I don't trust it with my inbox That is the correct starting position. Connect it read-only, leave the approval gate where it is, and read the audit log for a week. Every draft it writes sits in your drafts folder until you press send yourself. If it never earns the next permission, it never gets it.

Runs on your machine, only

The server binds to 127.0.0.1. There is no cloud copy of Roy, no hosted version of your data, and no port on the public internet — Funnel-style exposure is never enabled.

Your phone reaches it privately

Remote access is exclusively through Tailscale: HTTPS on a private network made of only your own devices. Not on the tailnet, not reachable.

Secrets in the OS keychain

API keys, OAuth tokens and the local password hash live in your operating system's credential store — never in a config file, never in the repo, never sent to us.

The approval gate

Every sensitive action — run a command, write a file, send mail, post, message, call, trade, unlock — is intercepted and waits for your tap. Deny means stop; Roy never retries around you.

An audit log you can read

Every tool call, every approval and every decision is appended to a plain-text log on your disk. When you want to know what Roy did and why, you read it — not a dashboard's summary of it.

Sessions that die

Logging into Roy needs your local password even on your own network. Sessions are held in memory, so Logout — or a restart — invalidates them everywhere at once.

Your account, your way in

A password (10+ characters, never a common one), a one-time code by e-mail, a passkey, or Sign in with Microsoft / Google — from which we keep only the verified address. Codes and sessions are stored hashed; five wrong guesses lock the door for fifteen minutes.

Export, delete, support access

Everything Roy holds for you can be exported or deleted from Settings. If you ever want us to look at a problem, you grant support access — time-boxed, logged, revocable — and we never have it otherwise.

Allowlists and always-confirm

You decide what's routine.

The gate is strict by default. In Settings you can add patterns that skip approval for actions you consider routine — a specific script, a specific recipient. Some patterns are in an always-confirm list and prompt regardless of any allowlist: recursive deletes, and — for the house — locks, garage, alarm, valves and stove plugs. Home devices are tiered: lights and media may be pre-approved; thermostat and away mode ask; the serious tier always asks.

What runs where

Server
Your PC · 127.0.0.1 · no public ports
Phone
HTTPS over your Tailscale network
Secrets
OS credential manager
Data
Your disk, your vault; no telemetry
Providers
Called on your keys, from your machine
Sends
Approved by you, logged to disk
This site
Name, email, plan, license key — that's all
What leaves your machine

Only what you connected, only on your keys.

DestinationWhatWhen
Claude / ChatGPTThe context needed for a turn — a thread, a note, your instructionEvery chat turn and every draft, on your API key
PerplexityA research questionWhen you ask for web research or the daily brief runs
Microsoft 365 / GoogleRead requests; a draft or send only after approvalInbox tracking, calendar, Teams asks, Drive reads
Slack / Telegram / iMessage bridgeReads; a message only after approvalWhen connected
TwilioCall audio and DTMFOnly during a call you approved
PXPA payment, payout or invoice you approved; the card or account tokens it keeps for youOnly when the money desk is on, on your own merchant account
QuickBooks / XeroReads nightly; an entry only after you accept itWhen books are connected
Roy's license serviceYour license keyOn first run and occasionally after — nothing else
Us, otherwiseNothingEver

Finance and money

The trading desk runs on a paper account until you deliberately set it live; every order passes a risk check, then waits for you. The money desk never moves money without a tap, asks two of you above a threshold, and treats a payee's changed bank details as a red flag: verify by phone first, two approvals for 30 days. Your transaction mirror is kept for two years, then exported to CSV and pruned.

Self-improvement

When Roy changes its own code it does so on an isolated branch, runs the test suites, and opens a pull request. It cannot merge; you are the merger.

Reporting a problem

Found something? Email hello@roy.example with "Security" in the subject. We acknowledge within two business days and credit you if you'd like.

Read the code path, not the marketing.

Every claim on this page corresponds to something you can inspect on your own machine after you install: the bind address, the keychain entries, the allowlists, the audit log.

Give it a week. It'll know your job.

Private beta is open to a small group of operators. Tell us what you run and we'll get you in.

Get early access