Trust

An agent that acts needs a spine

Answering wrong is embarrassing. Acting wrong costs money and trust. So Inflection is built the other way round from a chatbot: every capability starts closed, and the rules that keep it closed are yours to write.

The confirm gate

The customer authorises the action

Inflection proposes; a person decides. When Inflection is about to click or type, it stops and surfaces exactly what it intends to do — the action, the target, and the value — and waits.

  • 01The proposed action is shown in full before it runs.
  • 02Declining is a first-class outcome, not a dead end.
  • 03A confirmation covers one action — it is not a standing permission.
  • 04High-stakes actions can require a human on your side as well.
Proposedclick "Cancel & refund"
Targetdata-inflection-id="refund-btn"
Value$128.40 · Visa ···· 4429
Stateawaiting confirm
Boundaries

You write the lines it cannot cross

01

Never-act list

Name the actions Inflection may only explain, never perform. Closing accounts, deleting data, anything irreversible.

declared
02

Protected fields

Mark inputs Inflection must never fill, even when a customer asks it to.

declared
03

Limits

Cap what an action may be worth. Above the line, it goes to a human.

declared
04

Learned boundaries

When an escalation reveals a rule, Inflection proposes it — and it stays a proposal until someone accepts it.

approved
05

Values it will not touch

The safest way to handle a card number is never to receive one. Payment-card and identity-number patterns are refused at the input, not filtered afterwards, and training a login captures the shape of the form rather than what was typed into it.

refused
Audit

Grounding is what makes it auditable

Because Inflection resolves a specific element rather than clicking a coordinate, every action has a name. That is the difference between a log you can defend and a video you have to interpret. Every entry is attributed too: account-specific actions require the customer's own authenticated session, so Inflection never holds a master key to your customer base and cannot reach one account from another's conversation.

01

Per-action record

What ran, on which control, with what value, and who confirmed it.

02

Session replay

Step through any conversation exactly as it happened.

03

Escalation trail

What was attempted before a human took over.

04

Change history

Who verified a flow, who accepted a boundary, and when.

Data & infrastructure

Where things live

01

Region pinning

Deployments are provisioned to a chosen region; conversation history and customer data stay in it.

regional
02

Encryption

Encrypted in transit, and at rest on managed storage.

standard
03

Isolation

Each workspace's knowledge, memories, flows, and credentials are scoped to that workspace.

per-workspace
04

Keys

Public keys for the browser, secret keys for the server. Rotatable, scoped, revocable.

scoped
05

Self-hosting

If none of the above is enough, run the whole stack yourself.

available
Compliance

Where we actually are

Inflection is early, and we would rather tell you that than imply a badge we haven't earned. Here is the honest status.

Security architecture & controlsin place
Self-hosted / private deploymentavailable
SOC 2 Type IIon the roadmap
Penetration test reporton the roadmap
Security review for design partnerson request

If your procurement process needs something specific, ask — we will tell you plainly whether we have it today.

Deployment

Runs where you need it to run

01

Inflection cloud

Fully managed. Fastest path to a live resolution, with region selection at provisioning.

managed
02

Your cloud

Deployed into your own account and region. Your infrastructure boundary, your network rules.

private
03

Self-hosted

The whole stack — agent runtime, worker, storage, crawler — runs on infrastructure you control.

self-hosted
04

Data residency

Pin the deployment to a region so customer data and conversation history never leave it.

regional