KEORISRETURN TO KEORIS

PERMISSION IS THE ARCHITECTURE

Powerful enough to act.
Bounded enough to trust.

KEORIS separates what the model can suggest from what the application is allowed to do. Important boundaries are enforced in application code, not left to a prompt.

APPROVED FOLDERSFile tools are restricted to locations you explicitly approve.
CONFIRMATION GATESMoves, renames, deletes, shutdowns, and other sensitive actions pause for approval.
NO UNRESTRICTED SHELLThe AI model cannot directly execute arbitrary Windows commands.

Files and destructive actions

Screen vision and screen driving

Browser isolation

Web pages run in isolated sessions without access to KEORIS files, settings, keys, or internal controls. Camera, microphone, and location requests are denied by default. Downloads are disabled in the current browser stage, and local-file URLs are refused.

Cameras and remote access

Known limitations

Security claims should include the uncomfortable parts. The Windows installer may be unsigned and trigger SmartScreen. Windows secure storage protects keys when available, but some non-OpenAI connected-service secrets can fall back to plain text in the local settings file. Optional cloud features necessarily send the disclosed data to their providers.

See the full Privacy page for network destinations and local-storage behavior.