What Luna will and will not do with your business.
An operator that can send email, answer your phone and work in your tools needs hard limits, not good intentions. These are the ones she runs under today, on every business we build her for. Each one is enforced in her code, not just written in her instructions.
You decide how much she does alone
She works from day one. Any job you want held for your OK, you say so once and it waits for you.
- Three settings, per job: she acts on her own, she drafts and it waits for your OK, or she drafts and nothing leaves. She starts on the first, and you can move any job down whenever you like.
- Approval has to come from you: a reply from your own inbox, Slack or phone, or the Approve button in your portal. The approve step is built so she cannot approve her own work.
- An approval covers the exact message you saw. If the words change, it needs a new OK. Approvals that sit too long expire.
- A teammate cannot approve a card they created themselves.
- When she reaches out first, instead of replying, texts and DMs only go out between 9am and 9pm, and she caps how often any one person hears from her in a day and in a week.
The least-trusted reader decides
She writes for everyone who can read a message, not just the person she is answering.
- When someone outside your team is on an email thread, she answers as if they can read everything, because they can. Your private notes stay out.
- A Slack channel only counts as internal when every member in it has been checked. Until then, she treats it as public.
- In a meeting, work questions are answered to you privately, not in front of the room.
Your business stays yours
Your operator runs on its own server, built for your business alone.
- Each client gets a dedicated server. Her memory of your business lives on it and never mixes with another client's.
- The disks on every client server are encrypted.
- You connect your tools with your own accounts. Keys you hand her stay on your server.
- You can ask what she remembers about someone, and have her forget it.
- You can give a teammate a permission for a set time, and it ends on its own.
Secrets do not travel
A password or API key should only ever live in one place.
- If someone pastes a key into the chat, it is scrubbed before the message is stored or read by the model.
- Keys go in through a secure box, never through the conversation, and she never repeats one back.
- Our own logs are swept for anything shaped like a credential, and an alert fires if one shows up.
We check our own walls
Guards are only useful if something checks they are still there.
- Automated checks run every hour to confirm our database exposes nothing to the public internet, and they alert the moment that changes.
- Those checks also watch the protections themselves, so a guard that gets switched off does not go unnoticed.
- When she writes a new skill for herself, it is set aside and reviewed before it is allowed to run.
Everything on the record
You should never have to take her word for it.
- When she declines to do something, the refusal is recorded and shows up in your morning note.
- She tells you what did not happen, not just what did.
- Your report is counted from real records, including the messages she chose not to send and why. When a number is not available, it says so instead of showing zero.
What we are not, yet
We are not SOC 2 or ISO 27001 certified. Nothing on this page is an audit, and we will not show you a badge we have not earned.
What we can show you is how she is built. If your business has a security review, a vendor questionnaire, or rules about where data may live, bring it to the call and we will go through it with you line by line.
Ask us the hard questions.
On a design call we map where an operator can take work off your plate, and exactly what she will be allowed to do on her own.
Weighing your options? See how Luna compares to AI sales agents.
