Memava

Safety

Your Chief of Staff drafts. You decide what leaves.

An assistant that reads your mail needs someone keeping watch over it. In Memava Chief of Staff that watch is written into the software, not left to the AI's good judgment. Below are the six rules it enforces, how we check each one, and the limits we have not closed yet.

The software, not the AI, decides what counts as your tap.

Six rules it enforces

Six rules the software enforces

Each rule says what it means for you, where it stops, and how we check it. A rule without its limit would be an overclaim, so every one carries both.

Nothing goes to anyone else without your tap.

What this means for you. Your assistant can only draft. An email or a calendar invite to someone else leaves after you approve that exact draft.

Where it stops. Two exceptions are ones you set up yourself: a standing rule you approved for named people, which works up to a daily limit and which you can revoke at any time, or a group helper you set to work on its own inside its group. If your assistant has a mailbox of its own, it also sends short fixed-wording notes from that address, such as scheduling offers, confirmations and acknowledgements, and when someone picks one of the times it offered, it books that meeting on your calendar and invites them. Anything in its own words waits for your tap unless you raise its level yourself, and anything in its own words to someone new, any attachment and any amount of money always waits.

How we know. Tests in our code try to send a draft that was never shown to you, and an automatic send with no approved rule behind it. Both are refused before anything happens.

You see who it goes to before you tap.

What this means for you. The approval card names who the email goes to, including Cc and Bcc, and the subject, and it carries the whole draft. When the text is long it is folded, and the full email opens on the same card. Approve, edit or cancel from there.

Where it stops. The card shows you the draft. Deciding whether it should go is still your call.

How we know. Tests check that the card lists To, Cc, Bcc and Subject, and that in the web app a first tap on Approve for a long email opens the full text instead of sending it.

A tap cannot be faked, and a draft cannot change after you saw it.

What this means for you. When a draft is shown to you, it is signed with a key kept for your account. If anything changes the draft afterward, or an approval arrives that did not come from you, it is refused. The assistant itself cannot read that key.

Where it stops. The signature proves the draft is the one you saw. It does not judge whether sending it is a good idea. That is what your tap is for.

How we know. Tests rewrite a draft after it was shown, and plant a fake approval and a fake standing rule. All three are refused.

It cannot read the keys to your accounts.

What this means for you. The files that hold your connection keys are closed to the assistant, and anything that looks like one of those keys is stopped before it can leave in a web request, a search or a draft.

Where it stops. The check knows the key files and key shapes on its list. A secret you paste into a chat yourself is ordinary text to it.

How we know. Tests try to read a key file, and to send a copied key out in plain, web-encoded, base64, hex and reversed form. Every attempt is blocked.

What it reads is text, not orders.

What this means for you. Mail from your connected accounts is marked as outside text before the assistant reads it. After it reads mail or a web page, it cannot change your rules in that same turn without your tap, and a draft written after reading mail never goes out under a standing rule. It waits for you.

Where it stops. It can still draft a reply that an email asks for, and a cleverly written message can still shape a draft. That draft stays a draft until you approve it.

How we know. Tests feed it a message that tries to give orders and check that it arrives marked and defused, try a rules change right after reading mail, and send a draft written after reading mail through a matching standing rule. The rules change is refused and the draft is held for your tap.

Your assistant has a room of its own.

What this means for you. Each client's assistant runs in its own container, with its own folder and its own keys. Its operating instructions and its permission settings are mounted read-only, so it cannot rewrite them, and the app refuses any path that leads from one client's folder into another's.

Where it stops. The containers share a server, and the people who run Memava can reach that server.

How we know. Tests plant a link from one client's folder into another's, and check that the files holding its instructions, its permissions and its secrets are mounted read-only. The app refuses the link.

Inside the app, a page called How your assistant is protected runs the tests behind five of these rules on the live system every few hours and shows each result by name. It is switched on account by account today, not yet for everyone.

Not yet

What we do not promise yet

  • We can reach your data. Your assistant's folder sits on our server, and the people who run Memava can technically open it. Nothing in the software stops that today.
  • No disk encryption at rest yet. Encrypting the server disk at rest is in progress and not in place.
  • No sealed hardware. Confidential computing, where a server is sealed so that even we could not look inside, is not in place. It is on our list for the future, and we will not name a date until it exists.
  • The AI model sees what it works on. To write a draft, the text it needs is sent to an AI model provider named on the privacy page.
  • Connected services see their part. Reading your mail and calendar happens at Google or the other provider you connected, and a send you approve goes out through your own account there.
  • No certification. We hold no formal security certification and claim none.

The privacy policy lists what we store, who processes it and for how long. To take access away or have your data deleted, see delete your data.

Check it yourself

Ask Memava to show you

Copy one of these into your assistant as its own message. The software answers them itself, so the reply comes from your real records, not from the AI's guess.

A plain summary of what your assistant keeps in memory for you.

what do you know about me

The rules it follows for you: who may interrupt you, quiet hours, and its daily limit.

show my rules

To remove something, send forget followed by the thing, for example forget my old office address. It shows you what it would remove and asks you to confirm before it deletes a word.

Looking for how the shared vault keeps notes and AI agents apart? That is on the security page. The assistant itself is on the Chief of Staff page.

Download for Mac Ask us a question