How a mistake is kept cheap.
An agent that can send email, move money and publish pages has to be wrong safely. These four things are what make the worst case survivable.
Sending, paying, publishing, cancelling and merging all stop and wait for a person, with the full thing attached. You choose what else joins that list; the agent cannot remove anything from it.
Work happens on isolated machines with nothing shared between jobs — its own disk, its own browser session, destroyed when the run ends.
Each connection carries the narrowest scope that completes the task, granted by you and revocable one tool at a time. Kaer never escalates its own permissions or asks for admin.
Every action the agent took and every approval a person gave is timestamped and attributable. Export it, or query it from your own systems.
A browser session is not a loophole.
Kaer reaches some services through a native connector and the rest by signing in and using the web app. That distinction changes how access is scoped — not whether the gates apply. A payment made in a browser stops for approval exactly like one made through an API.
- Native connections: explicit API scopes, revocable individually
- Browser sessions: isolated machine, destroyed at the end of the run
- Same approval gates, same audit trail, either way
Not training material.
Your correspondence, documents, customer records and code are the context the agent works from. They are not used to train models. Enterprise adds private compute options and retention controls on top of that.
Security, answered.
Are you SOC 2 or ISO 27001 certified?
Can the agent send email as me without approval?
What happens to the machine a job ran on?
How do I revoke access?
How do I report a vulnerability?
Bring your
security team.
We would rather answer the hard questions before you buy than after. Book thirty minutes and ask them.
