Skip to content

Our trust principles

An assistant that acts for you is only worth having if you can trust it when you're not watching. These are the seven commitments Otto is built on.

Most assistants ask you to trust the company behind them. Otto's rules are enforced by a server, not by a model's good behaviour. They run where you choose, in code you can read, and they leave a record you can check.

1. Authority comes only from you

Nothing Otto reads can give it permission.

2. The model never sees your secrets

Passwords, codes and card numbers stay out of it.

3. Exact actions, run once

You approve one specific action. It never repeats on its own.

4. You can see everything

Every use, cost and app action is on record.

5. Your computer, your model

Otto runs where you choose, with the provider you choose.

6. Open by default

Open source code. Analytics off until you opt in.

7. Honest about limits

Every control says what it doesn't cover.

No single check makes an AI assistant safe, so Otto stacks independent ones. The model's judgement is the first layer, never the last.

flowchart LR
  you([Your request]):::accent --> model[Model<br/>plans, asks when unsure]
  model --> trust[Trust check<br/>exact app action]
  model --> vault[Vault<br/>task, account, website]
  trust --> world[Apps and websites]
  vault --> world
  trust --> record[(Record you can read)]:::accent
  vault --> record

Web pages, emails, files and app results are data. Only your messages, the instruction that created a schedule, and your explicit approvals can authorize an action.

  • Reads and changes to your own data run. Anything that reaches other people or deletes data needs authority from you.
  • When intent must be judged, a separate review sees only your messages and the action, never the content that suggested it.
  • Work Otto starts on its own can only read and draft.

How approvals work →

The model picks the account and the fields. The server fills in the value.

  • Vault checks the task, the account and the website's exact origin before it uses a saved value.
  • The value is typed into the verified field privately, and masked in everything the model sees afterwards.
  • Model provider keys never enter the sandbox, the browser or a prompt.

How Vault works →

An approval isn't a general "go ahead". It binds one action with its exact arguments.

  • Changing a recipient, an amount or a payload needs new authority.
  • A saved claim makes sure an approved action can't run twice, even after a double tap or a crash.
  • No action is retried automatically. If the outcome is unclear, Otto says so, and you check before anyone tries again.

One use, one result →

The full record is for every user, not an enterprise add-on.

  • Vault → Activity shows every use of a saved item, every question and every held attempt.
  • Settings → Trust & cost shows what every model call cost and every app change, send or deletion that ran.
  • A monthly spending limit stops new work before the next model call.

Spending and usage →

With the desktop app or a source install, Otto's server, database, workspace and browser run on your computer.

  • You bring your own model provider and pay it directly.
  • Commands run in a sandbox with no access to your files or keys.
  • In hosted mode, every user gets a separate runtime, database role, key, browser and workspace.

Your data and privacy →

You shouldn't have to trust a security claim you can't check.

  • Otto is open source under the Apache License 2.0, including the trust check, Vault and their tests.
  • Usage analytics stay off until you turn on Share usage data, and recordings never show your content.
  • Feedback reaches the Otto team only when you send it, and you can leave out the diagnostic report.

Analytics and recordings →

Security that overstates itself is worse than none, because people rely on it.

  • The review is a best-effort judge and can be wrong.
  • A website receives the values you let Otto submit, and can keep them.
  • The Otto server can read saved values while it uses them, and a hosting operator can decrypt hosted data.

Security model and limits →