The question is not whether it works. It is what happens when it is wrong.
Every serious buyer of an autonomous system asks that, and it is the right question. This page is the mechanism that answers it, what we can and cannot promise about your data today, and the shape of a pilot.
One seam, and nothing gets past it
The agent holds nothing
Read-only retrieval and one tool that proposes. No credential, no connector, no path to the outside world.
The gate is not ours to argue with
Selah evaluates against your tenant's policies and returns a decision, a reason and a trace id. OnDuty executes; it does not decide.
Fail-closed is the default path
No clean permit, no execution. A timeout, an error or an unclear answer kills the action, and nothing configures that away.
Holds go to a person
A held action waits in a review queue with the proposal, the reason and the context. Nothing expires into being sent.
The interesting question about an autonomous system is what it does when it is uncertain, when the network is slow, and when nobody is looking. All three answers here are the same: nothing happens.
What isolation means today, precisely
At the level of detail somebody doing diligence needs, including where it is weaker than an enterprise buyer would like.
| Concern | Today | On the enterprise tier |
|---|---|---|
| Tenant separation | Every query scoped by tenant. A workspace you do not belong to answers 404. | Same, plus a dedicated database on request. |
| Connector credentials | Encrypted at rest with a key held outside the database. | Same, with the key in your own key management. |
| Conversation content | Processed by a model vendor on our account. | Agents on your own machines; content never leaves your network. |
| Data residency | Not offered. | Through Selah jurisdictions, scoped during the pilot. |
| Audit | Every decision, permitted or refused, in a hash-chained trail with a verify endpoint. | Same, exportable. |
| Model training | Your data is not used to train shared models. | Same, in writing. |
| Third-party audit | None. No SOC 2 report. | None yet. We will not write otherwise. |
What a pilot actually looks like
Six weeks, one workflow, one team. Scoped narrowly on purpose: an evaluation that touches everything proves nothing about anything.
Week 1
Scope. The one workflow, the actions an agent may propose in it, and the guardrails over them.
This needs your operation in the room. It is the input we cannot supply.
Weeks 2 to 4
Connect and read. Sources are connected read-only and the Brain builds entities, memory and signals from what is there. Agents run in shadow.
Every decision is evaluated and logged. Nothing executes.
Weeks 5 to 6
Shadow off, on the workflow agreed in week 1 and nothing else.
You watch the decision trail, not the agent.
After
A hash-chained record of every decision the system made in six weeks, including the ones it was not allowed to act on.
That, rather than a demo, is what you take to whoever approves this.
Shadow mode is set on the Selah side and OnDuty honours the flag the gate returns. Nobody here can claim a tenant is governed in production while its shadow is still on.
Three ways to start
Explore
No commitment
A non-binding letter of intent, a quarterly conversation about the roadmap, and first refusal on a pilot slot.
Book a call →Pilot
Six weeks
One workflow, one team, dedicated setup and a weekly review, with the success criteria written down before week 1.
Book a call →Design partner
Co-build
We build against your edge cases, you get preferential pricing over twenty-four months and a quarterly say in what gets built.
Book a call →Where we are looking for design partners
Named because it is where the founders have operated, not because there are deployments to point at. There are none yet.
| Sector | The shape of the mess |
|---|---|
| Vehicle retail | Long cycles, quotes that go quiet, and a customer history spread across a CRM, a chat channel and an inbox. |
| Hospitality | High message volume against a small desk, where the same guest asks three people the same question. |
| Multi-location food service | One brand, many locations, and complaints that only look like a pattern read together. |
| Venues and events | Enormous demand in a short window, and context that has to be right the first time. |
The questions that come up
- What happens when the model is uncertain?
- Uncertainty is not the mechanism that protects you, and a confidence score is not a permission. The action is permitted, held or denied on your policy, and a held action goes to a person with the full proposal attached.
- Can it integrate with our stack?
- Source connectors exist today for Gmail, Google Drive, Google Calendar and HubSpot, plus WhatsApp and webchat as channels. Anything else is work, and we will say how much during scoping.
- Who owns the data?
- You do. It is processed to run your agents and is not used to train shared models. Logs, history and the decision trail can be exported.
- What does it cost?
- Enterprise has no published price on purpose. Everything below it has a price on the pricing page, read from the same place your card is charged from.
- How much of this is built?
- The seam, the executor, the review queue, the audit trail, the Brain, the source connectors and billing are built and running. Residency and agents inside your network are scoped per deal. There is no SOC 2 report and Google verification is pending.
Thirty minutes, and a real answer about scope.
We will walk one of your workflows, show you what the gate does with it, and tell you plainly whether a pilot makes sense.
On duty ·