Skip to content

Safety & boundaries

Handing an AI the keys, without handing it the building

Giving an assistant real control of a real website is only sensible if the platform underneath assumes it will sometimes be wrong. This page is what that assumption looks like in practice — the nets, the boundaries, and the parts we haven't built yet.

Between a mistake and your live site

Four nets, in order

Each one catches a different kind of wrong. You'd have to get past all four to have a bad day, and even then the fourth one un-does it.

01

Drafts, by default

Everything your AI does lands in a draft. The live site is a separate, already-published thing that a draft cannot touch. There is no “edit live” mode to accidentally be in.

02

Undo, 25 steps deep

Inside a draft, each change can be walked back one step at a time — before a publish exists to roll back to. This is the net that makes experimenting free.

03

A check before it goes live

Publishing runs the site check first: broken internal links, missing images, pictures with no description, heading order, orphan pages. It scores the site and lists what's wrong while it is still private.

04

Immutable releases

Each publish becomes a numbered release that is never edited again. Going back means pointing the live site at an earlier one — seconds, no rebuild, and your current draft survives.

Scoping

What your assistant can reach

The boundary isn't a rule we ask the AI to follow. It's what the server will answer, and it is decided before any prompt is read.

How the connection works
Your sites, and nothing else
The personal token your assistant uses is bound to your account. Another customer's site isn't hidden behind a permission check — it is not addressable.
Your plan, and nothing else
Tool access is filtered by plan on the server. On Standard, the e-commerce tools are not merely refused; they never appear in your assistant's list.
Rotate it yourself
Revoke the token and mint a fresh one from your console. The old one stops working immediately, and the new one is shown in full exactly once.
New tools fail closed
Every tool is classified against a plan scope. Anything unclassified defaults to staff-only, so a tool we ship tomorrow cannot quietly become reachable today.

Where things live

Your data

Form submissions
Stored with your site, on our infrastructure in your account. You get the email; you can export the lot as CSV or delete them. We don't mine them and there is no third-party form service in the middle.
Payment credentials
Held server-side by the platform. They are never written into a page, a draft, a release or a chat — which also means your assistant cannot leak what it cannot see.
Visitor analytics
First-party and cookieless. Pageviews and an approximate unique-visitor count, using a salted identifier that is rotated daily and never stored raw. Do-Not-Track is respected. Nothing follows a visitor to another website.
Google tools, if you add them
GA4, Maps or Ads run on your own keys and do use cookies — so the platform turns on a consent banner automatically the moment you enable one. Cookieless stays the default.
Your pages and photos
Yours. Exportable as plain files at any time, without asking.

How it's served

The runtime

Nothing runs when a visitor arrives
Published sites are static files served over HTTPS. There is no plugin layer, no request-time database and no customer code executing on our servers.
HTTPS everywhere, from minute one
Every site gets a certificate the moment it exists, renewed automatically. Custom domains get one as soon as their DNS resolves.
Publishes are atomic
The swap from one release to the next happens in a single move. A visitor sees the old site or the new one — never a half-written page.
Uploads are screened
Photos are re-encoded before they land, which strips camera and location metadata and neutralises anything hiding in the original file. Remote image fetches are restricted to public https addresses.

The other half of trust

What we haven't built

A platform that only lists its strengths is telling you half a story. These are real limits today — if one of them is a deal-breaker, better to know now.

  • One payment gateway today

    PayFast. Others get named when they're wired, not before.

  • Mailing-list signup is single opt-in

    It collects and de-duplicates addresses; it does not send a confirmation email yet.

  • One language per site

    Multi-language sites aren't supported.

  • No customer logins

    Member areas and gated content aren't part of the platform.

Still want to check something?

Ask. If the answer is “we don't do that yet”, you'll get it in those words rather than in a paragraph designed to sound like a yes.