Security & control

Powerful automation. Controlled by you.

An AI Business Team only earns trust if control, isolation and accountability are structural — not promised. Here is how 3rd Desire is built to behave.

Human approval, by design

  • Consequential actions — spending, publishing, outbound communication — are prepared by the AI team and executed only after approval.
  • Autonomy is a dial you control per department and per action type, not a switch someone else flips.
  • Separation of duties is enforced in the platform: the same actor cannot both create and approve governed records.

Data control & isolation

  • Each organization’s data is isolated with database-level access rules, not just interface filters.
  • Access is deny-by-default: a role sees nothing unless a rule explicitly grants it.
  • Your business data is used to serve your business — it is not shared across customer organizations.

Accountability & audit

  • Actions carry a record of who requested, who approved and what changed.
  • Approved business truth (offerings, brand assets, references) is versioned so you can see what agents relied on.
  • Mistakes are recoverable: review trails make it clear where to intervene.

Responsible automation

  • No uncontrolled consequential actions: boundaries cover budgets, channels and data reach.
  • Bring-your-own-keys is planned for AI providers, keeping usage under your accounts and budgets.
  • We label capabilities honestly — available, planned or coming soon — instead of overselling.

What we publish

Our Privacy Policy covers what we collect and why; the subprocessors page lists the service providers behind the platform; account deletion explains how to leave and take your data's fate with you. Security researchers can reach us via the address published in security.txt.

3rd Desire is pre-launch: we do not claim third-party certifications we have not completed. When formal attestations exist, they will be listed here.