How JUWEL OS stays yours.
Your approval before anything consequential, your keys on your device, and your OS instance under your control.
The short version
JUWEL OS is built so you stay in control: consequential actions are designed to pause for your approval, your signing key is generated on your device, files and memory live with your instance, and material actions she takes can be signed and reviewed in the OS ledger.
Approval gates
JUWEL OS is designed so consequential outward actions pause for your explicit approval before they run. Enforcement has layers that match the code:
- Server-gated consumer tools (single-use token): Today the effectful set is create calendar events (
gcal.create) and create Gmail drafts (gmail.draft). Those tools require a single-use approval token minted and spent server-side. There is no bypass flag for server-gated tools. - Company OS: Consequential action classes — send, publish, spend, hire, sign, delete — always require human approval. Company agents draft; they do not self-approve outward acts.
- Client approval UX: Other OS surfaces may show approval cards as product UX. The server inventory above is the authoritative enforcement set and expands as tools ship — we do not claim every possible action is server-token-gated until it is on that list.
When JUWEL fetches the live web for you, that fetch is SSRF-hardened: private, internal, and cloud-metadata addresses are blocked, and the gate resolves DNS itself to defeat rebinding.
Keys and the action record
- Your instance generates an ECDSA P-256 keypair in your browser (WebCrypto). The private key stays with your instance.
- Material actions can be canonicalized, hashed (SHA-256), signed, and chained so you can review what ran in the OS. The ledger is the source of truth for signed events.
- The ledger is part of how the OS works, not a separate product you buy.
Your data
- OS files, memory, and chat history live with your instance, exportable at any time.
- We don't sell your data. Billing runs through Stripe; we never see your full card number.
- No BAA today. Do not submit protected health information (PHI).
Where we are honest about limits
Compliance posture (see also Privacy):
- SOC 2 Type I: In progress — target 2026 H2. Not attested.
- SOC 2 Type II: Target 2027 H2.
- HIPAA: No Business Associate Agreement today. Do not send PHI.
- GDPR / UK-GDPR: Rights via product controls (export, deletion path, privacy policy) — aligned, not certified.
- ISO 27001: Roadmap (post SOC 2 Type II). FedRAMP: out of scope.
If your procurement needs specifics, ask us directly. Found a vulnerability? Mail info@juwel.ai with "SECURITY" in the subject, or security@juwel.ai. We read those first.
We maintain an internal product-readiness threat model; critical session issues are tracked until closed. We do not claim that scoped agent keys cannot escalate until residual risks are closed.
