It reads everything. It changes nothing without you.
Edgekeeper is a private AI brain on a server we run for your business, wired into the systems you already use. We built it on the assumption that someone will eventually try to attack it through the text it reads — a message, a file, a note somebody typed. So it runs read-only, in a fresh sandbox that is thrown away after every question, on a machine with no door to the open internet.
Everything on this page is running today. Nothing here is a roadmap. Where something is not done yet, it is written down at the bottom rather than left out.
Where does my data live?
On a server dedicated to your business, in our own cloud, with no address on the public internet. Getting to it at all means coming through one hardened entry point, from our controller, with a key. Your records and everything the brain learns about your business are yours, with full export rights written into the contract.
Can it change anything in my systems?
Not on its own. Every question is narrowed to read-only before it runs, so the brain is never holding a credential that could change something. A change happens only after a person on your side approves one specific action, and that approval is good for exactly one action, once.
What does the AI actually see?
Only what the person asking is allowed to see, and only what a specific question asks for. We never bulk-ship your data to a model. It asks narrow questions of your systems, one at a time, and every one of those looks is written down where you can read it. Passwords and keys are never part of the conversation.
Who on my team can see what?
You decide, by area — service, money, sales, company records, equipment, projects, people — and the database itself enforces it. Someone without the money area gets nothing where a billed figure would be, and neither does the brain when it answers for that person. It is not a rule the AI is asked to follow. The information never reaches it.
What if someone tries to trick it?
We assume they will, through the text it reads — a message, a device name, an attached document. Every piece of text that comes out of your systems is wrapped and labelled as information rather than instruction before the brain sees it, and its standing rule is that only your people can authorise an action. We ran that attack on purpose and published what happened.
What happens if the server is attacked?
Each question already runs in a throwaway sandbox with no way onto the internet except one narrow, named door, so there is nowhere for anything stolen to go. The machine itself is held to a written standard of checks, and one that fails a check is not allowed to run. The record of what happened leaves the machine every ten minutes, to somewhere the machine cannot reach back into.
What about HIPAA and audits?
We hold no external audit report and no certification, and we would rather say so than let a badge imply one. What we have is a written standard of controls, each with what it prevents and the check that proves it. For practices handling patient records the condition is explicit: we deploy on the API tier under a zero-retention agreement, and the paperwork is signed before any patient data moves.
What do you not claim?
Quite a lot, and we publish the list at the bottom of this page. No audit report, no certification, no outside security test yet, nothing about what an engine provider keeps, and no promise that everything is backed up and rehearsed while that is still only partly true.
What we don't claim.
- No external audit report. We have not been through one, and we do not imply otherwise.
- No ISO certification.
- No third-party penetration test yet — our own standard and drills are what we publish, and a third party's result will be listed here when there is one.
- No claim about what an AI provider retains. We do not control it, so we do not describe it.
- Nothing is backed up that we have not told you is backed up, and we have not yet rehearsed a restore in front of a customer.
Found something wrong with any of this? Tell us and we will fix it and say what we fixed.
Write to security@automatededge.ai. If you would rather talk through how this applies to your own practice, the call is free and there is no pitch.
Free · 30 min · no pitch. Or read what Edgekeeper actually is.