AI prepares. A person authorizes.
This is not a setting you enable later. It is the rule the whole system is built on — the reason Stack Mind can do real work without asking you to gamble your business on it.
Stack Mind’s security model rests on one rule: the AI prepares work — it looks up data, drafts messages, creates tasks — and a person authorizes anything irreversible, like sending communications, deleting information, or moving money. Access is explicit and limited, secrets are never exposed to the model, and data is isolated by user and organization. We do not claim the system is unhackable and we do not claim certifications we have not earned.
Why this rule exists
The most common mistake in AI product design is the opposite of what we do: give a model broad, standing access to a company’s systems and hope it behaves. It works fine in a demo. It fails the first time the AI misreads a situation and the action it took cannot be undone.
Stack Mind starts from the other direction. Every agent — Hanna doing the day-to-day work, BOSS answering from company knowledge — operates with a defined, limited set of permissions. They can look things up, draft things, organize things, and tell people things. What they cannot do is act on the world in a way that cannot be reversed, without a person saying yes first.
This is not caution for its own sake. It is what makes it safe to let an AI actually touch your operation instead of just chatting about it. A system that only ever answers questions is easy to trust and useless to run a business on. A system with unrestricted access is powerful and impossible to trust. The boundary in between is where Stack Mind lives.
That boundary shows up the same way in every part of the product: in what an agent is allowed to call, in what data it can see, and in which actions pause for a human before they execute. It is architecture, not a policy document.
What the AI does alone, and what it never does alone
The line is drawn by what can be undone.
The AI executes on its own
- Look up real data across the business to answer a question
- Prepare a draft — a message, a reply, a summary — for someone to review
- Create and assign a task with an owner and a due date
- Notify the right person on the team that something needs attention
- Organize information into company knowledge so it can be found later
- Follow up on something already agreed, without inventing new commitments
Always waits for your approval
- Send a mass communication to customers or contacts
- Delete information from the business records
- Move money or commit financial resources
- Change a person’s permissions or access level
- Publish anything externally — a post, a page, a public message
- Take an action with no record of who approved it
How this is actually enforced
Six controls, in plain business language, not security jargon.
Explicit, limited permissions
Each agent is given a defined list of what it is allowed to do. There is no default of "everything" that someone has to remember to restrict.
Secrets never reach the model
API keys and credentials are handled by the system around the AI, never placed in front of the model itself.
Data isolated by user and organization
One company’s information does not mix with another’s, and access inside a company follows who is asking.
Roles and permissions per person
What a person can see and do in Stack Mind depends on their role, not on what they happen to type.
A record of what mattered
Important actions are logged, so "who approved this and when" has an answer instead of a guess.
Measured AI usage
AI consumption is tracked, so cost and volume are visible instead of being a surprise on a bill.
The questions every buyer asks
Straight answers, including where the honest answer is "it depends" or "not yet."
In the infrastructure Stack Mind runs on for your account, kept separate from other organizations using the platform. It is not scattered across the personal devices or inboxes of individual team members.
The people in your organization, according to the role they have been given, plus the agents acting within the permissions set for them. Access outside your organization is not part of how the system is built.
No. Your business data is used to answer your questions and do your work — it is not pooled with other customers’ data or used to retrain a shared model on your behalf.
Your data belongs to your business. If you decide to stop using Stack Mind, we work with you to get your information out in a usable form.
We do not claim errors are impossible — no system can honestly claim that. What we control for is blast radius: irreversible actions require human approval precisely so a mistake stays a draft, not a consequence.
What we do not claim
- We do not claim Stack Mind is impossible to breach. No one who is honest with you can claim that about any system.
- We do not claim certifications we have not obtained — no SOC 2, no ISO, no HIPAA or GDPR compliance badge unless and until it is actually earned.
- Some modules are more mature than others. In a live demo, we tell you plainly which parts are solid today and which are still in active development.
Ask us anything about how this works
Security questions deserve a real conversation, not a page. Tell us what you need to verify and we will walk through it with your case in mind.