Every client stays inside its boundary
Resources are scoped by tenant and partner; cross-boundary attempts are tested before flows are closed.
SECURITY & COMPLIANCE
Aymar applies security at the core so partners can sell automation with understandable limits and operating evidence.
Review my caseResources are scoped by tenant and partner; cross-boundary attempts are tested before flows are closed.
First-party integrations expose curated actions that are disabled by default.
Activity, access and actions support incident investigation and operating evidence.
Configurable content passes controls designed to reduce malicious instructions and context leakage.
Each channel must disclose automated interaction and retain a path to human service. Breaching Regulation (EU) 2024/1689 can be fined up to €15 million or 3% of global turnover (art. 99).
Minimisation, retention, rights and responsibility mapping are designed in, not added later. Breaching GDPR can be fined up to €20 million or 4% of global turnover (art. 83).
Existence (the integration is connected), visibility (the agent has the label), audience (internal or also client-facing) and the requester's permissions. No action crosses all four without explicit authorisation.
Third-party credentials are encrypted with AES-256 and an independent key per client, stored outside the database.
Encryption keys rotate without interrupting the service; when a client is deactivated, their credentials are cryptographically erased.
After a connection is created, only its identifying hint stays visible — never the full value, not even through the public API or the MCP server.
Encrypted traffic uses a hybrid, classical and post-quantum, key exchange wherever the terminator already supports it.
CONTROL CENTRE
Toggle each boundary to see why commercial automation needs more than a good prompt.
PLAIN WORDS
The party that legally sells to the end client: invoices, charges and is accountable for the sale. In your case, that is you.
"Bring Your Own Key": using your own AI provider key instead of Aymar's. It is optional.
A standard protocol for connecting an external tool server to an AI agent. Third-party MCPs are opt-in, under your responsibility.
The list of actions a worker is allowed to run. Anything not on the list stays blocked by default.
We review the flow, data and integrations before deployment.