Trust roadmap

Here is exactly what we can prove about your privacy today, per hosting option, and what we can't yet. We'd rather show you the gap than word around it.

Last reviewed 25 August 2026

How to read this

This is the trust-claim ladder we hold ourselves to internally, published in full. Every privacy claim alwyse makes, the hosting option it applies to, and whether it has shipped. The rule behind it is one line: no sentence on this site may run ahead of what's actually shipped on the tier it describes. Publishing the ladder is how we keep that rule, because public copy can't quietly outrun a public table. You'll see gaps below. Showing them is the point.

The boundary is the promise

Everything alwyse captures, and everything it works out about you, lives inside a trust boundary. Crossing buys capability: a frontier model, a web search, a calendar. Not crossing keeps everything in, and costs you features. Both are legitimate. Today the shipped guarantee is narrower than a choice over every kind of crossing: you choose each model destination, and every model crossing is destination-guarded and recorded.

So we will never tell you "your data never leaves." That sentence would be false the moment you asked alwyse to search the web, and it would make your own choice look like our broken promise. What we owe you instead is a hard boundary, honest records for the paths that ship, and the levers we can actually give you. The general consent dial and unified egress gate do not exist. Below is exactly how much is built.

Two tables, two jobs

The first table says what is true today. It is the only one that grants anything: every sentence we publish is checked against it, row by row, and nothing else. The second says where each claim is headed. It is a roadmap, not a permission, and you should rely on none of it.

Statuses, not dates

We don't publish target quarters or version numbers. A slipped date on a trust page is just a broken promise, which costs a trust brand more than never promising. In the first table, each cell says where the guarantee actually is:

  • Shipped Real today. Rely on it now.
  • Building Part of it is real; the rest is named below.
  • Not offered Not part of this tier, by design or because the tier doesn't exist.
  • Not applicable The question doesn't arise here. The cell says why.

The three hosting options

Self-host

You run alwyse on your own machine or server. Your data and local models stay on your box, and there is no alwyse operator in the path at all: you are both. You may separately choose an external model destination. Today the public reach claim remains your own network.

Cloud

The managed service we operate. Today this is the beta most people use during early access. It has standard isolation, which is a real protection but not operator-blindness. What it does promise is that running it never requires reading you.

Cloud Confidential

The operator-blind managed tier: sealed inside confidential-computing hardware, with attestation your own device can check, and models that run inside the seal. It does not exist. Its boundary remains an unscheduled architecture placeholder, so nothing here claims it in the present tense.

As shipped today

A point-in-time snapshot, last reviewed 24 August 2026. This is what is true now, on the tiers as they exist now. The plain-language detail, and where each guarantee stops, is spelled out claim by claim below.

alwyse trust claims by hosting option and current status, as of 24 August 2026
Claim Self-hostYou run it; no operator in the path CloudStandard isolation; today, the beta Cloud ConfidentialDoes not exist yet
No alwyse employee or cloud admin can read your content Not applicableNo alwyse operator is in the path. You are both operator and user Not offeredStandard isolation, by design. See the next row for what Cloud does promise Not offeredTier not available
Your device can cryptographically verify that blindness Not applicableNothing to attest; you hold the keys Not offeredNothing to attest Not offeredTier not available
Running the service never requires reading your content Not applicableWe run nothing ShippedYour own cell and database; a content-free control plane and logs; model content goes directly to the selected provider. Alwyse-funded options disclose provider-side usage metadata Not offeredTier not available
You can run alwyse entirely inside the boundary ShippedLocal models. Nothing crosses, and no crossing is even recorded BuildingBackground cognition uses a named Alwyse-operated destination outside the cell; interactive thinking may use a separately selected external provider Not offeredTier not available
Recorded model crossings, and the levers over them BuildingEvery model crossing is owner-selected, destination-guarded, and recorded; the general consent dial and unified egress gate do not exist BuildingThe same model guard and record ship; Alwyse-funded options also disclose the provider account and visible usage metadata Not offeredTier not available
You can reach your own instance remotely without alwyse seeing your traffic BuildingNative pairing, pinning, and direct-to-relay switching ship; production isolation and live cross-client verification remain. Public reach is still LAN only Not applicableYour cell is reached directly; no relay in the path Not offeredTier not available
You can take everything out (export) ShippedFull local takeout ShippedServed by your own cell, never our control plane Not offeredTier not available
You can delete anything (deletion) BuildingLive removal, physical compaction, backup expiry, and the first owner-sealed restore path ship; total-loss recovery guarantees remain BuildingThe same deletion path and the same remaining recovery limits where managed backup is configured Not offeredTier not available
Boundaries you set over sources BuildingSource choice and severability ship; rules about subjects do not exist BuildingThe same source boundary ships, with the same missing subject boundary Not offeredTier not available
Understanding you can see and correct BuildingInspection and conversational or confirmation-mediated correction ship; per-fact edit and remove controls do not BuildingThe same surface and the same limits Not offeredTier not available

We never blur the tiers. A sentence that is true only on self-host names self-host. "Provably private" with no tier attached is a violation of our own rule, and Cloud Confidential does not exist, so nothing here claims it in the present tense.

Where each claim is headed

This table grants nothing. It is the roadmap, not the permission, and only the table above describes what you can rely on today. Where a claim has a target, it is the moment it becomes real, never a date. Where it has none, we say so.

Where each alwyse trust claim is headed, by hosting option, with its target or the absence of one
Claim Self-host Cloud Cloud Confidential
Operator-blindness Not applicableNo operator in the path NeverBy design; standard isolation is the tier No targetDesigned, not scheduled
Attestation Not applicableYou hold the keys NeverNothing to attest No targetDesigned, not scheduled
Content-blind operation Not applicableWe run nothing Shipped Arrives with the tierSuperseded by operator-blindness
In-boundary models ShippedLocal models Before broad launchA shared model host inside the boundary Arrives with the tierInference inside the seal
Recorded crossings, and the levers over them No targetRecorded, guarded model destinations and the named interactive/background owner decisions ship; the general consent dial has no target No targetThe same shipped model controls and the same unscheduled general consent gap No targetThe general consent gap does not disappear with the tier
Remote reach without alwyse seeing it Before broad launchNative activation ships; production isolation and live verification remain before a public remote-reach claim Not applicableReached directly Not applicableReached directly
Export Shipped Shipped Arrives with the tier
Deletion Before broad launchLive removal and physical compaction ship; no-resurrection recovery completes the unqualified claim Before broad launchThe same recovery guarantees remain; managed backups also become owner-sealed Arrives with the tier
Source boundaries and subject rules No targetSource choice and severability ship; subject rules and compartment-aware enforcement are not scheduled No targetThe same shipped source boundary and unscheduled subject boundary No targetThe same seam whenever the tier is offered
See and correct your understanding No targetInspection and conversational or confirmation-mediated correction ship; per-fact controls are not scheduled No targetThe same shipped correction path and unscheduled per-fact controls No targetThe same seam whenever the tier is offered

Two rows say Never, and we'd rather write that than leave them looking merely unfinished. Cloud will not become operator-blind, because standard isolation is what that tier is. There are also no commitments beyond broad launch for the general consent dial, subject-boundary rules, per-fact understanding controls, or Cloud Confidential. When one is scheduled, this table will say so.

Claim by claim

No alwyse employee or cloud admin can read your content

  • Self-host Not applicable
  • Cloud Not offered
  • Cloud Confidential Not offered

On self-host, this question doesn't arise. There is no alwyse operator to be blind: the person who installs it is both the operator and the user, and that is you. The sentence is trivially true, which is exactly why we won't sell it to you as something we provide. The moment an operator does enter the path on self-host — when you reach your box from your phone, over our relay — it becomes a real question, and it has its own row below.

On Cloud it is not true, and we won't pretend otherwise. Cloud uses standard isolation, the same kind most software you already rely on uses. That's a reasonable protection, but a determined administrator with infrastructure access could reach your data. This is not a gap we are racing to close on that tier: standard isolation is the tier, by design. What we built instead is the next claim, and it is a real one.

Cloud Confidential is the tier that would close it without asking you to run anything, by sealing your content inside confidential-computing hardware. It does not exist. The approach is designed, no build is scheduled, and so we make no present-tense claim about it anywhere.

Your device can cryptographically verify that blindness

  • Self-host Not applicable
  • Cloud Not offered
  • Cloud Confidential Not offered

A promise you can't check is just a promise. Attestation is the proof: your device asks the hardware to show it's running the exact sealed software we published, before it trusts anything to it. On self-host there is nothing to attest, since you already hold the keys and run the code. On Cloud there is nothing to attest either, because Cloud is not operator-blind to begin with, and it never will be. Attestation is the defining feature of Cloud Confidential, and it arrives when that tier does. No build is scheduled, so until then we don't claim it.

Running the service never requires reading your content

  • Self-host Not applicable
  • Cloud Shipped
  • Cloud Confidential Not offered

"We don't offer operator-blindness" is a non-answer for the tier nearly everyone is actually on. So here is what Cloud does promise, and it is built, not planned. Your cognition lives in a cell of its own: its own instance, its own database, not a row in a shared table. The control plane that handles your account, your payment, and finding your cell holds only account records, content-free meters, and key fingerprints. It never receives your content. When alwyse thinks, your cell calls the selected model provider directly; that traffic never passes through our control plane. A destination may use a key you bring or an Alwyse-funded provider account. For the funded option, we can see the provider-side usage metadata named in the handling facts you accept, but never the model content through the control plane. Your export is served by your cell, never by our control plane. Each cell holds only its own keys, so a compromise of one is an event confined to one.

And our logs cannot contain your content, because the content is never captured to begin with. Where a log could be read by an operator, alwyse doesn't build the payload rather than building it and filtering it. A filter is a leak waiting to be misconfigured. What the model-crossing record names is the destination authority, never the path, the query, or a word of what was in it.

Here is the limit, stated in the same breath. We operate that cell. An administrator with access to the underlying infrastructure could reach the data at rest inside it. That is precisely why this is not operator-blindness and why we never call it that. This claim says running the service does not require reading you, and that we built it so it doesn't. It does not say we cannot.

You can run alwyse entirely inside the boundary

  • Self-host Shipped
  • Cloud Building
  • Cloud Confidential Not offered

AI needs a model to run, and where that model runs decides who sees your content. A model inside your boundary sees it and tells no one. A model outside it is a vendor, under their terms. On self-host you can run entirely on local models, and then nothing crosses at all: there isn't even a crossing to record.

On Cloud today, background cognition uses a named Alwyse-operated inference destination outside the cell boundary. You may separately choose an external provider for interactive thinking. The trust sentence names both legs rather than collapsing them into one route. A shared model host inside the boundary, so a Cloud instance can think without model content leaving, lands before broad launch.

A sealed enclave does not by itself stop your content reaching a model vendor. Those are separate questions, and conflating them is how a privacy claim quietly becomes false. What would keep content inside Cloud Confidential is that its models run inside the seal too, and that arrives with the tier. Even then, you may still choose to reach out to a frontier model from inside it. That choice stays yours.

Recorded model crossings, and the levers over them

  • Self-host Building
  • Cloud Building
  • Cloud Confidential Not offered

The model path is real. Settings presents only destinations granted for interactive and background thinking. Selecting either leg advances its destination generation and presents the exact current handling facts. No owner content is sent until you separately accept them. Every model crossing is then destination-guarded and recorded content-free, and the trust sentence names both selected legs.

The broader levers do not exist. There is no general consent dial, no compartment-aware routing, and no unified egress gate. You can choose and sever sources, and you can choose model destinations, but alwyse cannot enforce a standing subject rule over everything it may reach. We name the model guarantee precisely rather than letting it stand in for every kind of crossing.

You can reach your own instance remotely without alwyse seeing your traffic

  • Self-host Building
  • Cloud Not applicable
  • Cloud Confidential Not offered

Self-host is the one place where alwyse has no operator in your path, and the relay is the one thing that would put us there. Reaching the box in your home from a phone on a train means passing through something of ours. The backend relay substrate now exists, and native clients can pair, pin the instance identity, and switch between direct and relay paths.

The public claim still waits. The production sidecar must be isolated so it has no route to direct ingress, and the real path must pass live cross-client verification. Until both are true, public reach remains LAN and local discovery only. Remote reach and blind transport ship together or the copy waits.

You can take everything out

  • Self-host Shipped
  • Cloud Shipped
  • Cloud Confidential Not offered

Ownership means you can leave with everything you said and everything alwyse concluded. Full export ships today. It withholds only the recall search index, which a rebuilt instance recomputes from that cognition. The export is served directly by your own instance and never passes through our control plane, so it is content-blind on both offered tiers. On self-host and on Cloud you can do this now. On Cloud Confidential it arrives with the tier.

You can delete anything

  • Self-host Building
  • Cloud Building
  • Cloud Confidential Not offered

Ownership also means you can erase, and most of this is real today. In every alwyse app — on the web, on iOS, on macOS, and on Android — you can delete a single entry, or everything derived from a connected source, from your settings. It is gone from every live read immediately, cascading through whatever alwyse inferred from it, and any copy sitting in a backup expires within thirty days.

This is the standard we hold ourselves to, in the words alwyse uses with you:

Deleted means gone — removed from everything I show you right away, and then erased for real. Not hidden.

The live removal, physical compaction, service-readable backup expiry within thirty days, and the first owner-sealed quarantine-restore path ship. The row remains building because a total-loss recovery still needs continuous signing authority, an independently durable latest head, and control-plane journaling that prevents an old backup from silently resurrecting deleted content. Automated content-blind retention custody also remains.

None of this is in tension with alwyse keeping a faithful record of your life. Append-only is a promise about integrity, not a refusal to forget: it means your history is never quietly rewritten, and that corrections supersede rather than falsify. You decide what alwyse holds; alwyse decides only that it won't rewrite the past behind your back.

Boundaries you set over sources

  • Self-host Building
  • Cloud Building
  • Cloud Confidential Not offered

The source boundary ships on both offered tiers. You choose which accounts and sources feed alwyse, every connection can be severed, and a severed source stops supplying new material. That is the boundary this site means when it says you choose what feeds alwyse.

A subject boundary does not exist. You cannot mark a domain such as medical conversations off-limits, split work from personal cognition, or set a rule that routing, retrieval, and egress then enforce. The consent dial, compartment-aware routing, and unified egress gate are not built or scheduled. We do not describe source choice as enforcement over subjects.

Understanding you can see and correct

  • Self-host Building
  • Cloud Building
  • Cloud Confidential Not offered

The “You” surface ships on web, iOS, macOS, and Android. It shows standing profile facts, says whether you stated or alwyse inferred them, and puts controls over learned adaptation and standing instructions beside that view.

Correction is conversational or confirmation-mediated: tell alwyse it got something wrong, or reject a grouped confirmation, and the correction supersedes what came before. There is no per-fact edit or remove control. The true promise is that the understanding is visible and corrections reshape the model, not that every item is editable.

What these guarantees don't cover

Operator-blindness is a strong claim, so here is exactly where it stops. Stating the edges is the point, not fine print hidden at the bottom. Even where alwyse is operator-blind, the guarantee is about software and administrative access to your content. It does not defeat a valid legal order for data you hold; it does not claim immunity from someone with your unlocked hardware in hand; and it rests on the limits of the secure-enclave hardware we build on, which has documented failure modes of its own.

Some metadata stays visible so the service can run, even on tiers where its content is not: that a request happened, and its rough size and timing. We'd rather you know the shape of the guarantee than discover its edges later.

None of it covers an external capability you invoke. If you choose a frontier model, relevant content crosses the boundary and lives under that provider's terms; alwyse guards and records that model crossing. A web search or connected service can also cross the boundary under its own terms, but the general consent dial and unified record for every kind of crossing do not exist. What we owe you is the exact shipped guarantee, not one model control dressed up as a universal gate.

Deletion has an edge worth naming too. Removing an original takes it out of everything alwyse shows you, and anything alwyse derived from it updates in turn: a note that stood only on what you deleted goes with it, and a note that also drew on other things stays, with the deleted piece taken out. Such a derived note can hold a trace of the deleted content until alwyse next recomputes it. We say that plainly rather than imply a reach we don't have.

Why publish the gaps at all?

Because a transparency page that only shows the wins isn't transparent. Putting the whole ladder in public makes it self-enforcing: no marketing sentence can quietly claim more than this table admits. If you ever catch one that does, it's a bug. Tell us.

Where this is going

The destination is simple to state and hard to earn: a version of alwyse where you can have an instance nobody but you can read, without having to run it yourself, and where you can take it all out or delete it whenever you want. Note what that sentence does not say. It does not promise operator-blindness on Cloud, because standard isolation is what that tier is, and pretending otherwise later would cost more than admitting it now. It says you will be able to choose a tier where the guarantee holds.

We're not there yet. This page is the honest scoreboard of how far we've gotten, and it changes in the same breath the product does.