AICROFT / trust & privacy

Privacy should be specific.

Here is what the product currently does, what the activity history means, and where the evidence is not complete yet.

Your data stays yours

Within your AICROFT workspace, agent reads and writes are scoped to your account. This does not make a universal claim about every provider or deployment.

You control what the agent can access

You choose an agent's configured sources, instructions, cadence, and delivery settings. Scoped chat declines requests outside that agent's configured topic.

Recorded activity is reviewable

AICROFT records selected agent mutations and route outcomes in a redacted activity history. It is not a complete record of provider, worker, or external-system activity.

Secrets are not shown in workspace summaries

Telegram bot tokens are stored in server-only columns and omitted from client-safe agent summaries. Review your destination before deploying.

Bounded controls

Approvals and data controls

Deploy requests are held server-side for 15 minutes and must be approved once for the same user, agent, action, and configuration hash. Pause remains immediate as a low-risk control. You can export an agent as safe JSON or delete it with its AICROFT audit history; Telegram tokens are excluded from exports. Product audit events default to 90 days, with a 365-day maximum, and cleanup is an explicitly reviewed service-role operation.

Readiness, not a guarantee

What AICROFT does not claim yet

We do not currently claim universal no-training treatment across providers, complete logging, universal approvals, encryption standards, zero retention, provider-side or account-wide erasure, compliance certification, Gmail OAuth, or an independent security review. The scheduler worker is not connected, so configuring an agent does not mean reports have been sent.