Privacy & security
How your data is isolated, encrypted, and kept under your control.
We obsess over security so you don't have to. Perisclaw works inside your WhatsApp, with access to your conversations and the tools you connect. Protecting that data is the foundation of the product. The short version:
Isolated
Your assistant runs in its own sealed environment. Only you and your own agent can touch your data.
Encrypted
Your data and logs are protected with keys unique to your environment.
No telemetry
Perisclaw does not quietly collect activity logs about how you use it.
No training
Customer data is never used to train Perisclaw's or anyone else's models.
ISO 27001
Independently audited and regularly tested for vulnerabilities.
You're in control
You decide which chats and apps it can use, and can revoke access anytime.
The rest of this page explains each of these in detail.
Your data is fully isolated
Every session runs in its own sealed environment. Your data is never pooled with anyone else's, and it never leaves that environment. The only thing that touches it is your own agent, acting on the instructions you give it, inside secure cloud infrastructure. No one on our team reads it, and it's never used to train any AI model. What you put in stays yours.
Everything is encrypted
From the moment you sign in, your data is encrypted into a form that's unreadable without the right key. Keys are derived on demand rather than stored, so they're never left sitting somewhere to be stolen, and every user's keys are different, so identical pieces of data look completely different once encrypted. Both your data and your logs are protected this way.
We don't collect data about you
Perisclaw keeps no activity logs and no telemetry on you. Nothing about what you do is quietly collected or sent back. If something ever needs debugging, the only thing that can inspect your environment is your own agent, which can trace and fix issues on request. The one exception is feedback you choose to send. That is logged and visible to you, so you always know what was shared and when.
Your connections are guarded against attack
Your agent can connect to tools like your calendar and email, and be extended with skills and plugins. Every one of those connections is also a possible way in for an attacker. The main threat is prompt injection, where malicious instructions are hidden inside ordinary-looking content (a message, an email, a web page) to trick your agent into acting against you. Your agent runs in a secured runtime with strict safeguards against unauthorized prompts, scripts, skills, and tool use, and we vet every skill, plugin, and connection against these attacks before it's ever allowed to run.
We're independently tested and audited
We don't rely only on our own checks. We are ISO 27001 certified, which holds our controls to an external benchmark rather than our own judgment. Our systems also go through regular vulnerability testing, where we actively hunt for and fix weaknesses before anyone can exploit them.
Your data is never used to train AI
Your data is never used to train AI models, ours or anyone else's. We explicitly opt out of all model training on customer data. What you put in is used only to run your assistant, and nothing more.
Reporting something
For anything security-related, or if you notice something unusual, contact our support team.