TECHNOLOGY / PRIVACY & SECURITY

Your data.
Your server.
Your choices.

We set up your personal assistant, with the teams behind it and the folder structure they work in. We do the setting up, configuring and securing; there is little you need to do. And everything is in your company’s name: the server, the accounts and all the keys are yours.

This is how we set up every assistant. What we agree with you is in the agreement.

WHO DECIDES

You own it. We handle the rest.

Your assistant and the teams run on a server of their own and on accounts in your company’s name. What they remember is stored on your server. You decide what they may read, how long things are kept and which parts are switched on. In GDPR terms, you are the controller.

We do the work: setting up, configuring and securing the assistant, the teams and the folder structure. That is what we are there for. After delivery we close our own access together with you; after that we only come in when you let us in for help or maintenance.

THE AGREEMENT

Everything on paper, before we start.

The setup comes with a comprehensive agreement. It describes everything: which language and voice services take part and where they are, where your data is kept, who is responsible for what, and what happens if you stop. We do not publish that agreement online; you receive it before you sign.

We work for people who take privacy seriously. That is why you have all the room you need to read the agreement yourself first, or have your lawyer review it. That is how it should be.

HOW IT IS SECURED

Eight layers.
Each with the technology behind it.

In plain language what happens, and below it the technical terms for anyone who wants to check.

01

ACCESS

Only you log in, and a voice alone is never enough.

Your password is never stored in readable form, only as a strong hash. After five failed attempts, logging in locks for a minute. A voice that sounds like yours makes no one the owner: that takes your own logged-in device.

PBKDF2-HMAC-SHA256 (600,000 rounds, salted; older hashes are upgraded at login) · session stored as SHA-256 hash · cookies HttpOnly, Secure, SameSite=Lax · signed device tokens (HMAC-SHA256) · CSP, X-Frame-Options DENY
02

CONNECTION

No open web port to your server.

The server has no open web port. The app can only be reached through an encrypted tunnel, and administration works only with a key, never with a password.

Outbound encrypted tunnel · TLS 1.3 · app listens on 127.0.0.1 only · firewall allows ssh only · ssh with keys only · automatic security updates
03

PERMISSIONS

Acting needs your yes.

Your assistant works with six levels, from talking to sensitive actions. Acting needs your approval on your own logged-in device. Words such as pay, cancel or sign always make a request sensitive. Your assistant never pays, buys or signs, and stops before the payment screen.

Levels 0–5 · approval only by a verified owner · approval valid for 30 minutes · background work never above preparing
04

IN COMPANY

What a guest says does not linger.

When someone else talks to your assistant, or you are in company, it says nothing about you, your projects or your calendar. What a guest says is not kept in the request trail.

Guest mode · lower maximum levels in company and in meetings · inbox, queue and memory hidden from guests
05

SECRETS

Login details in a vault.

When your assistant logs in to a site for you, that password is stored encrypted on your server. It only goes to that one site, never back to the app or into a log. The vault key is not part of the backup.

AES-256-GCM, each item bound to its site · key derived from the server’s signing key · older items converted automatically · secrets in a protected file, never in code or logs
06

SOUND AND IMAGE

Text stays, sound does not.

When your assistant listens in, the sound goes to speech-to-text. It stays on your server only until the report is ready, so your assistant can go through the whole meeting once for who said what; then it is deleted and only the text remains. After transcription, a phone recording is deleted at the phone provider. Photos are deleted after two hours.

Audio kept only until the report is ready, then deleted · recordings deleted through the provider’s API, with a log line if that fails · photos 2 hours
07

YOUR FOLDERS

Reading, not writing.

We connect your project folders so that your assistant and the teams can read them but change nothing. Per folder we agree with you what is off limits, such as keys and password files.

Read-only connection · a separate read key per repository · sync only pulls, never pushes back · deny list per project
08

BACKUP AND LEAVING

A copy every day. Never held hostage.

A backup every day, with an encrypted copy outside your server and a trial restore every day that shows it really comes back. If you stop, you take everything with you in ordinary files you can read without us.

Daily backup, kept 14 days · external copy encrypted with AES-256-GCM · daily restore test · SQLite, Markdown and JSON

MADE TO MEASURE

What you choose at setup.

Where your server is

Germany or Finland.

How long conversations are kept

And whether sound is deleted afterwards.

Which parts are switched on

Calling, the listening line, the calendar, the external copy and the second thinking route: only what you use is on.

What your assistant may read

Per company, project and folder, with a deny list.

ABOUT ONEENO ITSELF

What we do with your data.

We are responsible for our own website, your reservation and the payment. That is in our privacy statement.

Read the privacy statement
THE TECHNOLOGY BEHIND YOUR TEAM

See how your assistant is built.