The Supersafe Promise
Super ambitious. Safe by design.
Four promises that apply to everything we build, from a Blueprint audit to a Hayek treasury.
Private by default
We collect the least data we can, protect what we keep and never sell it.
Honest
Grounded in real data. It cites its sources and says "I don't know" instead of guessing.
Supervised
A person approves anything important, and every action is logged so it can be checked.
Yours
Your data, your keys, your code. What we build for you belongs to you.
Security
How we keep agents and money safe.
Agents that act for you and software that holds real money need more than a login screen. These practices apply to everything we build.
Least privilege
Every agent gets only the access its job needs, one system and one action at a time. Nothing is shared by default.
People approve what matters
Payments, messages sent in your name, deletions and changes to access wait for a person to say yes.
Every action is logged
What an agent did, when and why is recorded in an audit log you can read, so anything can be checked after the fact.
Your data isn't training data
We don't use your data to train models, and we choose AI providers and settings that keep it out of theirs.
Your keys stay yours
With self-custody products like Hayek, you hold the keys. No one at Supersafe will ever ask for your recovery phrase.
Tested before trusted
Agents are evaluated on real tasks, including the ones they must refuse, before they reach a customer and again after every change.
Responsible disclosure
Found a vulnerability in supersafe.com or one of our products? Thank you. Tell us first and we'll work with you to fix it.
Report a vulnerabilityHow to report
- Email hello@supersafe.com with "Security report" in the subject.
- Include what you found, the steps to reproduce it and the impact you think it has.
What we ask of you
- Test only against accounts and data you own.
- Don't access, change or keep other people's data, and stop as soon as you've shown the issue exists.
- No denial-of-service, spam, phishing or social engineering.
- Give us reasonable time to fix the issue before you share it publicly.
What we commit to
- We'll acknowledge your report within three business days and keep you updated until it's fixed.
- We won't take legal action against good-faith research that follows these guidelines.
- With your permission, we'll credit you when we disclose the fix.