# Privacy & security

Canonical URL: https://docs.perisclaw.com/privacy-and-security

**We obsess over security so you don't have to.** Perisclaw works inside your
WhatsApp, with access to your conversations and the tools you connect.
Protecting that data is the foundation of the product. The short version:

### Isolated

Your assistant runs in its own sealed environment. Only you and your own
agent can touch your data.

### Encrypted

Your data and logs are protected with keys unique to your environment.

### No telemetry

Perisclaw does not quietly collect activity logs about how you use it.

### No training

Customer data is never used to train Perisclaw's or anyone else's models.

### ISO 27001

Independently audited and regularly tested for vulnerabilities.

### You're in control

You decide which chats and apps it can use, and can revoke access anytime.

The rest of this page explains each of these in detail.

## Your data is fully isolated

Every session runs in its own sealed environment. Your data is never pooled with anyone else's, and it never leaves that environment. The only thing that touches it is your own agent, acting on the instructions you give it, inside secure cloud infrastructure. No one on our team reads it, and it's never used to train any AI model. What you put in stays yours.

## Everything is encrypted

From the moment you sign in, your data is encrypted into a form that's unreadable without the right key. Keys are derived on demand rather than stored, so they're never left sitting somewhere to be stolen, and every user's keys are different, so identical pieces of data look completely different once encrypted. Both your data and your logs are protected this way.

## We don't collect data about you

Perisclaw keeps no activity logs and no telemetry on you. Nothing about what you do is quietly collected or sent back. If something ever needs debugging, the only thing that can inspect your environment is your own agent, which can trace and fix issues on request. The one exception is feedback you choose to send. That is logged and visible to you, so you always know what was shared and when.

## Your connections are guarded against attack

Your agent can connect to tools like your calendar and email, and be extended with skills and plugins. Every one of those connections is also a possible way in for an attacker. The main threat is **prompt injection**, where malicious instructions are hidden inside ordinary-looking content (a message, an email, a web page) to trick your agent into acting against you. Your agent runs in a secured runtime with strict safeguards against unauthorized prompts, scripts, skills, and tool use, and we vet every skill, plugin, and connection against these attacks before it's ever allowed to run.

## We're independently tested and audited

We don't rely only on our own checks. We are ISO 27001 certified, which holds our controls to an external benchmark rather than our own judgment. Our systems also go through regular vulnerability testing, where we actively hunt for and fix weaknesses before anyone can exploit them.

## Your data is never used to train AI

Your data is never used to train AI models, ours or anyone else's. We explicitly opt out of all model training on customer data. What you put in is used only to run your assistant, and nothing more.

**Success: You stay in control**

  Your data exists for one purpose: to make your assistant work for you. You
  control every connection and everything it remembers. See{' '}
  [Permissions & access](/permissions-and-access).

## Reporting something

For anything security-related, or if you notice something unusual, [contact our support team](https://api.whatsapp.com/send/?phone=919205759988\&text=Hi,%20I%20need%20some%20help%20with%20Perisclaw).

### [Control what it can touch](/permissions-and-access)

Chats, apps, and actions are all under your control.

### [Control when it acts](/chat-modes)

Decide how forward your assistant may be in every chat.