Security
ALPHA acts on your computer, so it is built around one rule: a suggestion from the AI is never permission to act. Here is how that works in practice.
Nothing happens without authorisation
- A fixed list of actions. ALPHA can only use a small set of defined actions (open an approved app, type into a window it opened, open or list a known folder, open a website, close a window it opened). It has no way to run scripts, shell commands or arbitrary programs.
- Plans are checked before you see them. Every step the AI proposes is checked against that list and its allowed inputs. Anything outside it is rejected.
- You approve what matters. Steps that change something on your PC wait for your approval. Approvals expire after 10 minutes.
- Each step is separately authorised. After approval, ALPHA’s cloud service issues a signed, single-use authorisation for that one step, valid for about a minute. The component on your PC that carries out actions checks the signature and that the step matches exactly what was approved before doing anything.
On your PC
- ALPHA runs as you, with your normal Windows permissions. It does not need administrator rights.
- Its components talk to each other over local channels that only your Windows user can open, and that require a shared secret.
- ALPHA types only into windows it opened, and closes only those windows. It never force-closes a window.
- After each step, ALPHA checks the result (for example, it reads back the text it typed). If it cannot confirm the result, it tells you rather than claiming success, and it does not silently repeat the step.
- Speech recognition runs on your PC. Recordings are not uploaded and not kept.
Sign-in and accounts
- Sign-in uses Google Identity Platform. ALPHA accepts only verified email addresses, and each action is recorded against the signed-in user.
- Your ALPHA session uses short-lived access tokens. On the desktop they are kept in the Windows credential store.
- The desktop app holds no cloud keys. It talks only to ALPHA’s own service, over encrypted connections.
In the cloud
- ALPHA’s service runs on Google Cloud in the asia-south1 (Mumbai) region.
- Each organisation’s data is kept separate, and the organisation is always taken from the verified sign-in, never from a request.
- Operational logs carry identifiers and fingerprints, not your instructions, audio or document content.
- An activity log records who approved what and when. Organisation administrators can review the AI requests made on their behalf.
What we have not done yet
ALPHA is in early access. We do not claim any security certification today. An independent penetration test is planned before general availability, and we will update this page as that work completes.
Reporting a security issue
If you believe you have found a security vulnerability in ALPHA, please email our security contact with details and steps to reproduce. Please do not test against other people’s accounts or data.