# A personal agent that keeps your secrets: the 2026 agents read through behaviour policy and encryption, and a privacy-first design on vaults, enclaves and the browser, sgit.ai

> In the five months to October 2026 the personal agent became a product category. Meta's Muse, OpenAI's dots, Google's Gemini Spark, Microsoft's Autopilot, Amazon's Alexa+, Apple's rebuilt Siri and a self-hosted open source project called OpenClaw all give a person an always-on agent with a computer of its own, a memory made of files, and connectors into email, calendars, messages and money. This article reads them through two lenses this site already uses. The first is RiskMandate's Agent Behaviour Policy: what each agent can reach, what it was asked to do, what stands in the gap, and what record it leaves. The second is the data: where the memory rests, who holds the keys to it, who processes it, who could be compelled to hand it over, and what happens to the people in it who never signed up. Read that way, the products are strong where they are strong, a separate permission authority is a real barrier on actions, and candid where they are candid, Meta's own engineers say today's protection against Meta reading the memory is policy rather than cryptography. The second half is a design for a personal agent on the technology this site describes: memory in vaults the host holds only as ciphertext, a behaviour policy as the permission authority, compute in the user's browser where a small model is enough and in an attested enclave when it is not, with a key for one task's data released by the user's device against the enclave's attestation and destroyed when the task ends, the frontier model called only for the step that needs it, and a folder per person with provenance that the person it describes can read. The two designs, the vendors' and this one, converge on files and no database and a page per person. The difference is who holds the keys, who can read the pages, and who pays for it. It ends with what exists today, what does not, and the question of who gives the mandate over information in the first place.

*Source: <https://sgit.ai/articles/a-personal-agent-that-keeps-your-secrets.html> · site v0.6.77 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.*

---

[Home](../index.md) / [Articles](index.md) / A personal agent that keeps your secrets: the 2026 agents read through behaviour policy and encryption, and a privacy-first design on vaults, enclaves and the browser

# A personal agent that keeps your secrets: the 2026 agents read through behaviour policy and encryption, and a privacy-first design on vaults, enclaves and the browser

By [Dinis Cruz](../about/index.md) · 2026-10-06 · updated 2026-10-06 · [v0.6.76](../admin/versions.md) · agentspersonal-agentsagent-behaviour-policyencryptionconfidential-computingenclaveswebgpuprivacydata-sovereigntyvaultssgitriskmandatemeta-museopenclawarticle

***Abstract:** In the five months to October 2026 the personal agent became a product category. Meta's Muse, OpenAI's dots, Google's Gemini Spark, Microsoft's Autopilot, Amazon's Alexa+, Apple's rebuilt Siri and a self-hosted open source project called OpenClaw all give a person an always-on agent with a computer of its own, a memory made of files, and connectors into email, calendars, messages and money. This article reads them through two lenses this site already uses. The first is RiskMandate's Agent Behaviour Policy: what each agent can reach, what it was asked to do, what stands in the gap, and what record it leaves. The second is the data: where the memory rests, who holds the keys to it, who processes it, who could be compelled to hand it over, and what happens to the people in it who never signed up. Read that way, the products are strong where they are strong, a separate permission authority is a real barrier on actions, and candid where they are candid, Meta's own engineers say today's protection against Meta reading the memory is policy rather than cryptography. The second half is a design for a personal agent on the technology this site describes: memory in vaults the host holds only as ciphertext, a behaviour policy as the permission authority, compute in the user's browser where a small model is enough and in an attested enclave when it is not, with a key for one task's data released by the user's device against the enclave's attestation and destroyed when the task ends, the frontier model called only for the step that needs it, and a folder per person with provenance that the person it describes can read. The two designs, the vendors' and this one, converge on files and no database and a page per person. The difference is who holds the keys, who can read the pages, and who pays for it. It ends with what exists today, what does not, and the question of who gives the mandate over information in the first place.*

The personal agents of autumn 2026 placed by two questions, where the compute runs and who can read the memory at rest, with the colour giving the strength of what stops the agent acting. Most products sit in the vendor's corner. The blue square is the design in the second half of this article. Positions are approximate and from the sources listed; a shipped confidential option would move a product a long way across the horizontal axis.

**Where this comes from, and how to read it.** A voice memo on 6 October 2026, after the previous article described [the agent team as it runs](../articles/the-agent-team-as-it-runs.md) and three days after Wired reported that Meta's Muse keeps a page on every person in its user's life. Every statement about a product below is dated and sourced; vendor claims are called vendor claims, press reports are called reports, and the two are not blended. This is not a complaint about the products. Several of them have a stronger barrier on actions than the team described last time, and the article says so. It is an attempt to read them with the two instruments this site already has, and then to design the alternative those instruments point to. Nothing in the second half is built; the status section says exactly what exists.

## In short

- **The category arrived in 2026.** An always-on agent with a cloud computer of its own, memory as files, connectors into the user's accounts, and a confirmation step before sensitive actions. Muse, dots, Spark, Autopilot, Alexa+ and Grok Bot share the shape; Apple put most of it on the device; OpenClaw put all of it on the user's own machine and became the design Meta acknowledged copying.
- **Lens one, actions.** Read as behaviour policies, the products differ most on the barrier. Muse's Sentinel is a separate permission authority for every connector action and every byte of network egress, which is a boundary. Rules, approval modes and confirmation prompts are settings. A self-hosted gateway leaves the barrier to the user. The mandate is unwritten in every case, and the terms place responsibility for the agent's actions on the person who instructed it.
- **Lens two, data.** Read for sovereignty, the products mostly sit in one corner: memory in the vendor's cloud, encrypted with the vendor's keys if at all, processed by the vendor's model, trainable by default unless switched off. Meta's engineering post says of today's Muse that it "does not prevent Meta from accessing data when necessary to support, secure or operate the service", and that the version that would is with trusted testers. Apple's Private Cloud Compute is the published design that does the most: stateless, attested, with the user's device wrapping keys only to nodes whose measurements are in a public log.
- **The people who did not sign up.** A page per person in the user's life is a memory about non-users. Meta's help page says such information is not linked to an account and that rights can only be honoured where it is. The regulators have noticed: the ICO names the "concentration of personal information facilitating personal assistant agents" as a novel risk, and the CNIL recommends partitioning memory by agent and process with automated expiry.
- **The convergence.** Two designs built for different reasons arrived at files, no database, and a page or folder per person filled in from evidence. The vendor's came from a harness; this site's came from the vault model. What differs is who holds the keys, who can read the pages, what stops the agent, and what pays for it.
- **The design.** Memory in vaults the host holds as ciphertext. A behaviour policy as the permission authority. Compute in the browser where a small model will do, in an attested enclave when it will not, with a key for one task's slice of the memory released by the user's device against the enclave's attestation and destroyed when the task ends. The frontier model for the step that needs it, with the step's inputs and no standing access. A folder per person that the person can read.
- **What exists.** The vaults, the one-way read keys, the write-only lanes, the behaviour policy, and the team running on them exist. In-browser decryption exists. The enclave integration, the attested key release and the per-task scoping are proposed, and the hard rows are named.

## The year the agent got a computer

The dates matter, so here they are. Google announced Gemini Spark on 19 May 2026, "a 24/7 personal AI agent" on a cloud machine that "keeps working in the background even when you close your laptop". Microsoft introduced Scout on 2 June, an always-on work agent "with its own identity, memory, computer and workspace", and renamed it Autopilot on 25 September. Apple rebuilt Siri on 8 June around an on-device orchestrator with Private Cloud Compute behind it. SpaceXAI opened Grok Bot to early beta on 11 August. Meta launched Muse on 8 September: "Muse runs on its own dedicated computer in the cloud, contained so no one else's agent can reach it." OpenAI launched dots at its developer day on 29 September, "always-on" agents where "each dot has its own cloud computer and browser". Amazon's Alexa+ had reached every US Prime member on 4 February. Anthropic's Cowork, from January, runs "on Anthropic's servers, in an isolated environment", and on the day this article was written its local-only mode for individual plans was withdrawn.

Behind all of them is a project that is not a company. OpenClaw, Peter Steinberger's MIT-licensed, self-hosted gateway, was first published in November 2025 under another name, went through three renames, and by March 2026 had a quarter of a million stars on GitHub. It connects whichever chat apps a person uses to whichever model they pay for, runs on their own laptop or server, and keeps its memory in files under their home directory. When researchers found that Muse's harness files were near-identical to OpenClaw's, Nat Friedman confirmed it: "We built Muse from scratch, but it is definitely heavily inspired as a product by OpenClaw." The lineage is worth stating because it says where the shape came from. The shape is a personal agent as a small operating system of files, and it was designed by someone building for themselves before it was productised by companies building for everyone.

Adoption followed. The download estimates for Muse in its first fortnight varied by a factor of two depending on which firm was counting, and were in the millions by every count. The question this article is about is not whether people want this. They do. It is what they are handing over to get it, and whether the same thing can be had for less.

| Product | Launched | Where the agent runs | Where the memory rests |
|---|---|---|---|
| Gemini Spark | 19 May 2026 | Google cloud VM | Google account and VM |
| Microsoft Scout, now Autopilot | 2 Jun 2026 | Customer's Microsoft 365 tenant | Tenant storage |
| Apple Siri AI | 8 Jun 2026, beta later in the year | On device; Private Cloud Compute for what the device cannot do | On device; the cloud keeps nothing |
| Grok Bot | 11 Aug 2026, beta | SpaceXAI cloud computer | Vendor cloud |
| Meta Muse | 8 Sep 2026 | Per-user VM in Meta's cloud | Text files in the VM |
| OpenAI dots | 29 Sep 2026 | Cloud computer per dot | Held by the dot; not user-viewable |
| Alexa+ | GA 4 Feb 2026 | AWS | Amazon cloud |
| Claude Cowork | 12 Jan 2026 | Anthropic cloud sandbox | Anthropic cloud, plus optional local files |
| OpenClaw | Nov 2025 onward, 2.0 on 30 Aug 2026 | User's own machine or server | Files under the user's home directory |

## Lens one: what stops the agent

[RiskMandate's Agent Behaviour Policy](https://riskmandate.ai/abp.html) reads any agent in four words. The reach is everything it can do, measured from the deployment: accounts, connectors, credentials, tools. The mandate is what the user asked for. The gap is the difference. The barrier is what stands in the way of each row of the gap, and it is typed honestly: a boundary is enforced above the agent's reach, a setting is a switch the agent's own account could flip, an expectation is a rule in prose, and none is none. The site's own wording: "a control bounds a grant only if it is enforced by something the grant does not include." [Footprint and blast radius](../articles/footprint-and-blast-radius.md) added what the agent actually did, read afterwards, and what a row would cost if used in full.

Two lenses for any personal agent. The first is about actions and is RiskMandate's vocabulary. The second is about the data: where it rests, who holds the keys, who processes it, who can be compelled, what trains and what deletes. A product can be strong on one and silent on the other, and the two are rarely advertised together.

**The reach is the user's life.** Every product above asks for connectors into email, calendar, documents, messages, payments and the browser, and the pitch is that the agent is useful in proportion to what it can reach. The Center for Democracy and Technology's Miranda Bogen put the consequence plainly to Wired: these tools "are actively soliciting users to plug their whole lives in", and "the breadth of access to information that these tools have will lead to a ballooning of what they know about users." In the vocabulary here, the reach is being maximised on purpose, and for an agent that acts in the world the reach includes sending, paying and inviting, three things that cannot be undone.

**The mandate is unwritten.** None of the products has the user write down what the agent is for before it runs, because the whole appeal is that it will work out what to do. That is a design choice with a cost: without a mandate there is no gap to inspect and no near miss to catch. The terms fill the vacuum with liability. Muse's supplemental terms: "You are solely responsible for the instructions, goals, and guidance you provide to Muse. You are also solely responsible for the actions Muse takes or directs in furtherance of those instructions, goals and guidance." The FTC's chairman said much the same in September 2026, rejecting the idea of agents as independent actors: those who instruct the tools are liable.

**The barriers are where the products differ, and one of them is a boundary.** Meta's Sentinel, in the engineering post's words, "is a separate host-side agent from your Muse. It is the sole permission authority for approval to perform actions with connectors to third-party services and for all egress over the network." Credentials are held apart: "Muse has no visibility into people's passwords or payment methods." That is a boundary in the policy's sense, enforced outside the agent's own process, and it is stronger than anything the team described in [the previous article](../articles/the-agent-team-as-it-runs.md) has on actions, where "no agent sends" is a prompt and a policy. OpenAI's dots have built-in rules, user rules that allow, block or require approval, read-only "proactive research" while the user is away, and manual password changes; those are settings, real and flippable. Spark is "designed to ask you first before performing high-stakes actions like spending money or sending emails"; Cowork has manual, auto and skip approval modes; Alexa+ confirms purchases. OpenClaw binds its gateway to the loopback interface, pairs unknown senders with a code, and offers a sandbox that is off by default; the barrier is whatever the user configures, and its own documentation says it "is not a hostile multi-tenant security boundary for mutually adversarial users".

**The footprint is uneven.** Muse "shows people a complete audit trail of everything it has done and plans to do", and the users who asked for the VM's filesystem got it, which Meta then made a feature. The dots FAQ, as reported, says users cannot view, delete or directly modify individual dot memories, which is a memory a person cannot audit. OpenClaw's footprint is the user's own disk.

**The blast radius was demonstrated, not argued.** The incidents of September 2026 are the reach being exercised by someone other than the user. A Mac zero-day in Muse's desktop app let any unprivileged local process redirect dictation to an attacker's server and capture or inject prompts; Meta fixed it within a day. A crafted link could make Perplexity's Comet exfiltrate data from the user's connected accounts; Perplexity added a classifier and a permission step. OpenClaw's January incidents included publicly exposed control endpoints leaking keys and chat histories and a supply-chain campaign of hundreds of malicious skills. The lesson is the one [the ultimate insider](../articles/ultimate-insider-three-collisions.md) drew: whoever takes the agent over inherits its reach and ignores its mandate, so the blast radius is defined over the reach, and the reach here is a person's accounts.

## Lens two: who can read what it knows

The second lens asks six questions, and the answers are in the policies and the engineering posts rather than the launch videos.

**Where it rests.** In the vendor's cloud, for every product but two. Muse: "Muse runs on an environment in the cloud called a virtual machine ('VM'). This is the core environment where Muse keeps information you share." Dots: a cloud computer per dot. Spark: a Google VM. Apple: on the device, with a cloud that keeps nothing. OpenClaw: the user's own machine.

**Encrypted, by whom.** This is the question the products answer least. Muse's privacy policy does not say; Meta's engineering post does: the Secure VM "restricts access to your data by Meta personnel through operational policies. It does not prevent Meta from accessing data when necessary to support, secure or operate the service." The protection today is policy. The Confidential VM, "where the whole VM, including a person's data and conversations with Muse, is encrypted with a key only they hold, so not even Meta can access it", is "intended to cryptographically and verifiably prevent Meta from accessing data in your VM", is with a small group of trusted testers, and is promised for later in the year, with external auditors given the design and source. That is a serious commitment and it should be held to. The dots FAQ does not disclose encryption or key holding. OpenClaw's data is on the user's disk, but reviews of version 2.0 note that its secret store is not encrypted at rest, so "the user holds everything" includes holding it in the clear. Apple's design is the one to study: the user's device "will wrap its request payload key only to the public keys of those PCC nodes whose attested measurements match a software release in the public transparency log", and the nodes are stateless, so "personal data leaves no trace".

**Who processes.** Meta's own models on Meta's infrastructure. OpenAI's. Google's, with "Keep Activity" required for Spark, which means human reviewers may see some data and retention of up to three years under Google's Gemini terms. Apple's foundation models on Apple silicon, and since June on Google Cloud too, inside Intel TDX and NVIDIA confidential GPUs with "at least two separate roots of trust from independent vendors". Alexa+ uses Anthropic's Claude through Bedrock as well as Amazon's models. OpenClaw sends prompts to whichever provider the user chose, under that provider's terms. In every cloud case the model sees the plaintext of what it is asked, which is unavoidable; the question is whether anything else does, and for how long.

**Who can be compelled.** Whoever holds plaintext or keys answers a legal request. A policy that restricts staff does not remove the ability; the engineering post's sentence says so about Muse, and would say so about any product in the vendor's corner. Only a user-held key removes the ability, and only an attested, stateless design removes the ability during processing. The [previous article](../articles/the-agent-team-as-it-runs.md) made the same point about the team's vaults: the host's blindness is a property of the mathematics, not a promise, and so it holds against the host's own staff and the host's own lawyers.

**Training and ads.** Muse's policy says "You decide whether we can use your interactions with Muse to train and improve our AI models", and the setting is reported as on by default; identifiers are removed first; the policy adds that "Muse doesn't share your conversations or the data in your virtual machine with Meta ad systems." Dots on personal plans train unless the general "improve the model" setting is off; business plans do not. Spark trains if Keep Activity is on, which it must be. Apple states that nothing is trained on from Private Cloud Compute requests.

**Deletion, and the people who never signed up.** Muse's policy: "Muse may still 'remember' information it learned from what you deleted." And then the question Wired raised. The extracted instructions tell Muse to keep "a page for every person in the user's life", refreshed hourly, with sections for facts, history, the relationship, what is in common, open threads and how to strengthen it, and to use only the evidence available because "invented details are worse than an empty page." Those pages are about people who are not users. Meta's help page for them says their information "is not stored in a way that allows Meta to reasonably identify which information belongs to a particular person", and therefore that Meta "can only honor data subject rights in relation to information that is linked to a Meta account or stored in a way that allows Meta to identify which information relates to a particular person." A person with a page has no route to it. The supplemental terms place the consent problem on the user, who warrants that they have "obtained all necessary permissions, consents, licenses, and authorizations" including "consents (where required) from third parties whose personal information may be processed".

The regulators have started on this. The ICO's agentic AI horizon note of 8 January 2026 lists among the novel risks the "concentration of personal information facilitating personal assistant agents" and the problem of "determining controller and processor responsibilities through the agentic AI supply chain". The CNIL's exploratory note of 20 July 2026 recommends "partitioning of memory by agent and by process (with size limits and automated expiry)", sandboxing, risk-tiered actions with human approval for the higher tiers, and a user kill switch. GDPR's Article 25(2) requires that "by default, only personal data which are necessary for each specific purpose of the processing are processed", and Article 32 names "the pseudonymisation and encryption of personal data" first among the measures. A page per person, refreshed hourly, filled from a connected inbox, is a hard thing to reconcile with the first of those, and a memory the vendor can read is a weak showing on the second.

## What pays for it, and how much to trust

Muse is free for a large allowance with $20 and $100 tiers, and Mark Zuckerberg said at Connect that the expectation is "over time we will profit by taking a small fee from transactions". Dots are included in OpenAI's paid tiers. Spark needs Google's top subscription. Apple sells hardware. OpenClaw is free and run by a foundation. None of these is a reason to distrust a product. It is a reason to notice that most of the companies in the vendor's corner are companies whose other products are advertising and engagement, that an agent which knows the pages of everyone in your life is an unusually complete profile, and that the policy promising the agent's data stays out of the ad systems is a policy. How much to trust is then a personal arithmetic: what the agent does for you, against what the reach would cost you if someone else drove it, against what a change of policy would cost you later. The point of the second half of this article is that the arithmetic does not have to be done that way.

## The convergence

Here is the thing that made the previous article worth writing before this one. Strip the branding from Muse's memory and from the team's CRM and they are the same shape. Muse keeps structured text files in a per-user machine, a page per person, started sparse and filled from evidence, with sections a person would recognise. The team keeps plain JSON and Markdown in a vault, a folder per person, with a record, an append-only ledger, every message with provenance and a hash, and a graph of what the person cares about. Both refuse to invent: Meta's instruction is that an empty page beats an invented detail; the team's rule is that a fact without a source is a bug. Both arrived at files and no database. Meta's shape came through OpenClaw, from a developer building a harness for himself. The team's came from the vault model, where a file is the thing that can be encrypted, versioned, hashed and read with a read key, which is the argument this site has made since [What sgit is](../articles/what-sgit-is.md).

Same shape, different keys. A vendor's per-user memory as its extracted instructions and policies describe it, beside the team's folder per person. The rows beneath are where they part: where the files live, who can read them, what stops the agent, whether the subject can ask, and what pays for it.

The convergence is good news, because it means the privacy question is not a question of architecture. The files can be the same files. What differs is who holds the keys to them, who can read them, what stops the agent, whether the person described can see their page, and what business the whole thing is paying for. Those are the rows a design can change without changing the shape.

## A privacy-first design on this technology

What follows is a design, not a product. It uses the pieces this site documents, names the pieces it would need that do not exist, and places the hard rows where they belong, in a build brief rather than in the claims.

Three zones. The user's device holds the keys and does what compute it can. The vault host holds ciphertext and never a key. When a task needs more than the device has, it runs inside an attested enclave that receives a key for one task's slice of the memory. The model provider sees the step the enclave sends and nothing at rest.

**Memory in vaults the host cannot read.** The agent's memory, the pages per person included, is a vault: every file, filename and commit message encrypted on the user's side before it leaves, the host holding ciphertext, sizes and timings and nothing else. The key hierarchy gives three credentials with three reaches: a vault key that writes, a read key derived one way that only reads, and an append lane that only adds. The agent's own working memory is a vault; a shared memory with a partner or a team is another; what the agent may show a third party is a read key to a vault that holds only that. Nothing trains on any of it because nothing but a key-holder can read it. This part exists, and the [team runs on it](../articles/the-agent-team-as-it-runs.md).

**A behaviour policy as the permission authority.** Muse got one thing right that the team has not yet built: a separate authority that decides every connector action and every byte of egress, outside the agent's own reach. In this design that authority enforces a behaviour policy the user can read. The reach is measured from the connectors and keys the agent holds. The mandate is written, in the user's words, before the agent runs, and amended from the near misses afterwards. Each row of the gap has a barrier typed honestly, and the authority is where the boundaries live: which connectors, which lanes, which keys, which recipients, which hours. The send stays with the person for anything irreversible, by default, and the policy can relax that one row at a time with a record. The footprint is read from the vault afterwards, by the user or by a reviewer with a read key and no production access. This part exists as a vocabulary and as a team's practice; the authority that enforces it is the first thing to build.

**Compute where the user can see it, or where nobody else can.** Three places, chosen per step by budget rather than by architecture.

*The browser or device first.* WebGPU is in all four major browsers as of Safari 26 and Firefox 141, and in-browser inference stacks run models of up to about three billion parameters on a current phone and seven or eight billion on a laptop with sixteen gigabytes of memory, at speeds that are usable for triage, classification, extraction, embedding, search and summaries. Those are most of what a personal agent does between its big steps. The vault client already decrypts in the browser; the small model can read what it decrypts without the plaintext leaving the tab. What is not feasible locally today is frontier reasoning over long contexts and multi-hour tool loops, and the design does not pretend otherwise.

*An attested enclave when the device is not enough.* The cloud vendors sell confidential compute to small companies now. AWS Nitro Enclaves produce a signed attestation whose measurement a key service can require before releasing a key, though an enclave has no network, no persistent storage and no GPU. Google's Confidential Space has run on H100 GPUs in general availability since June 2026, releases data only to a workload whose image, container and VM all pass attestation, and states that "the workload operator has no access to the data, and can't control access to it either." Azure's confidential VMs with an H100 in confidential mode have been available since 2024 at roughly a quarter more than the unencrypted equivalent, with key release gated on attestation claims. The design the enclave should copy is Apple's: the user's device checks the enclave's measurement against a published image and wraps the key itself, rather than trusting the cloud's key service to do it.

*The frontier model only for the step that needs it.* With the step's inputs and no standing access to the memory. Where a provider offers attested inference, Cohere's shipped in September 2026 and Google publishes prompt-encryption SDKs for its confidential GPUs, the step can run there; where it does not, the policy records that this step's inputs are seen by a provider under its terms, and the user decides which steps those are.

Temporary access to one slice of the memory, controlled with a public key. The device scopes the task to files, the enclave attests, the device verifies and wraps a fresh key to the enclave's public key, the host serves ciphertext, the step runs and encrypts back, and the key dies with the task. The grant, the attestation and the card stay in the vault as the footprint. Proposed; the rows to verify are in the text.

**Temporary access to one slice, controlled with a public key.** This is the mechanism that joins the vault to the enclave, and it is the part the memo asked for. The user's device decides, per task, which files the agent step may read: this person's folder, this week's mailroom, nothing else. The enclave boots a measured image and attests, producing a public key signed by the hardware root. The device verifies the measurement against the published image and wraps a fresh data key for exactly the scoped files to that public key. The enclave pulls the ciphertext, decrypts in memory, runs the step, encrypts its results back to the vault, and discards the key at the end or at a deadline of minutes. The grant, the attestation and the step's card are written to the vault as files. No standing key sits in any cloud. The scope is least data rather than least privilege: an agent step cannot reach what it was not handed a key for. The deciding seat is the user's device, which can be offline for every step it runs itself. And the record is complete by construction, because every grant is a file a read key can later show.

**A folder per person that the person can read.** The pages exist, because they are useful, and the previous article's three classes apply to them: public, private-ish and personal, with personal refused by policy and checked for. Every fact carries its source. The person described can be sent their folder, as a "what we know about you" pack, and correct it. That is the answer to the non-user problem this design can give on its own: not that the page does not exist, but that it is held under the user's keys, kept to what the work needs, and shown on request to the person it is about.

**What the enclave operator still sees, and what remains open.** Timing, sizes and traffic shape are visible to the host in every scheme. The attestation roots are the hardware vendors', so trust moves from the agent vendor to the chip vendor and the cloud; Apple's requirement of two independent roots is the only consumer design found that addresses this. Physical attacks on memory buses, a passive interposer for about a thousand dollars in one published case and an active one for under fifty in another, have extracted keys from SGX and SEV-SNP, and in late 2025 were extended to DDR5 and to the chains that NVIDIA's GPU attestation depends on; the vendors call physical access out of scope. A security firm's review of Nitro's key-service integration in August 2026 noted that the key owner can always ask the cloud vendor to restore a default key policy, which is a boundary with a support ticket behind it. These are not reasons to abandon the design. They are the rows of its own gap, to be typed honestly in its own policy.

## What exists today, and what does not

**Exists.** Vaults with client-side encryption, one-way read keys and write-only append lanes, documented with their limits on this site and running under a team of twelve agents. The Agent Behaviour Policy as a vocabulary and as that team's practice, with barriers graded. Messages between agents as files. A folder per person with provenance. Decryption in the browser. Confidential compute with attested key release from three cloud vendors, with GPUs on two of them. In-browser inference for small models. A published design, Apple's, for client-wrapped keys to attested, stateless nodes.

**Does not exist.** A permission authority that enforces a behaviour policy outside the agent's reach, in this estate. An enclave image for an agent step, with its attestation checked from a browser without a vendor service in the loop. The per-task key release from the user's device to that enclave. A scoped read of a vault, where a key opens some paths and not others, which today is approximated with one vault per scope. Key revocation in sgit, which its limitations page says plainly does not exist, so a leaked key still means a new vault. Signed commit authorship, so that in a shared vault an agent's identity comes from its branch rather than a signature. Any measurement of what the three-zone split costs in time and money for a real day of a real person's agent.

**The build order, in five steps**, to be written up as a brief: the permission authority as a policy-enforcing proxy for connectors and egress, run beside the agent; scoped vaults, one per task class, until scoped reads exist; a browser-first agent for triage, search and summaries over a decrypted vault, measured; one enclave step on one cloud, with the device-side attestation check and key wrap, measured against the same step run unprotected; and the pack a person can be sent about themselves, generated from the folder.

## The question underneath

The design above answers how a personal agent can keep a person's secrets from the host, the vendor and the model, and how a person can see what it keeps about them. It does not answer the question the Wired piece raises underneath, which the previous article also left open. The information that fills a page about a person was given, by that person, to the user, in an email or a message or a conversation. It was not given to an agent, and not to whatever the agent passes it to. Who gives the mandate over a piece of information is a different question from who holds the key, and it gets a document of its own. What this design offers is that whatever the answer turns out to be, a policy per agent, a rule per relationship, a key per task and a memory that can be shown to its subject are the mechanisms it would need, and they are the same mechanisms that keep the secrets.

## Threads woven here

- [The agent team as it runs](../articles/the-agent-team-as-it-runs.md): the setup whose properties this design generalises, and the three classes of information.
- [Footprint and blast radius](../articles/footprint-and-blast-radius.md) and [Six agents, one inbox](../articles/six-agents-one-inbox.md): the vocabulary of lens one, and why the barrier column is the honest one.
- [The ultimate insider](../articles/ultimate-insider-three-collisions.md): whoever takes the agent over inherits its reach.
- [The identity we wanted to give the agents](../articles/the-identity-we-wanted-to-give-the-agents.md): why no secret can live inside an identity provider, which is the same argument one layer down.
- [Memory is not a spectator sport](../articles/memory-is-not-a-spectator-sport.md) and [Introducing fractal semantic graphs](../articles/introducing-fractal-semantic-graphs.md): memory as files with provenance, and the grammar a page per person uses.
- [What sgit is](../articles/what-sgit-is.md), [Vault credentials](../docs/credentials.md), [the security model](../security/index.md) and [Limitations](../docs/limitations.md): the three credentials, what the host sees, and what does not exist yet.
- [Before you give an agent a connector, give the connector a twin](../articles/connector-twin-before-you-deploy-an-agent.md): the footprint recorder at the line where the reach is exercised.

## Sources

- Meta, [Introducing Muse](https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/), 8 September 2026; Tarek Sheasha, [How We Built Safety Into Muse](https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse), 8 September 2026; [Muse Privacy Policy](https://muse.ai/privacy), effective 17 September 2026; [Muse Supplemental Terms](https://muse.ai/terms), 8 September 2026; [Information for people who don't use Muse](https://www.meta.com/help/artificial-intelligence/4532990443643263/).
- Lily Hay Newman and Matt Burgess, [Muse Creates Detailed Profiles of All Your Friends and Family](https://www.wired.com/story/muse-creates-detailed-profiles-of-all-your-friends-and-family/), Wired, 3 October 2026.
- Ana Maria Constantin, [Nat Friedman on Muse and OpenClaw](https://thenextweb.com/news/meta-muse-openclaw-friedman-soul-md), The Next Web, 22 September 2026; [the filesystem export finding](https://cryptobriefing.com/meta-muse-filesystem-download-exploit/), 24 September 2026; [the Mac zero-day](https://venturebeat.com/security/meta-patched-muses-zero-day-but-security-teams-still-lack-visibility-into-what-the-agent-can-access), September 2026; [Zuckerberg on transaction fees](https://finance.yahoo.com/technology/article/metas-zuckerberg-says-muse-ai-agent-will-take-a-small-fee-from-transactions-234639802.html), 23 September 2026.
- OpenAI dots: [TechCrunch](https://techcrunch.com/2026/09/29/openai-launches-dots-its-bubbly-agentic-avatar/) and [The Next Web](https://thenextweb.com/news/openai-dots-always-on-ai-agents-cloud-computers-devday), 29 September 2026; the [privacy FAQ](https://help.openai.com/en/articles/20001529-dots-privacy-security-and-safety-faqs), read through search summaries and marked as reported.
- Google, [Gemini Spark](https://blog.google/innovation-and-ai/products/gemini-app/next-evolution-gemini-app/), 19 May 2026; [Gemini Apps privacy notice](https://support.google.com/gemini/answer/13594961).
- Microsoft, [Introducing Scout](https://www.microsoft.com/en-us/copilot/blog/2026/06/02/introducing-microsoft-scout-your-always-on-personal-agent/), 2 June 2026, and [Autopilot](https://blogs.microsoft.com/blog/2026/09/25/introducing-the-new-copilot-with-home-code-and-autopilot/), 25 September 2026.
- Apple, [Siri AI](https://www.apple.com/newsroom/2026/06/apple-introduces-siri-ai-a-profoundly-more-capable-and-personal-assistant/), 8 June 2026; [Private Cloud Compute](https://security.apple.com/blog/private-cloud-compute/), 10 June 2024; [Expanding PCC](https://security.apple.com/blog/expanding-pcc/), 8 June 2026.
- Anthropic, [Claude Cowork](https://support.claude.com/en/articles/13345190-get-started-with-claude-cowork); Amazon, [Alexa+ general availability](https://www.cnbc.com/2026/02/04/amazon-alexa-plus-us-releas.html), 4 February 2026; SpaceXAI, [Grok Bot](https://venturebeat.com/orchestration/spacexais-grok-bot-turns-agents-into-persistent-digital-coworkers-that-can-operate-your-apps-for-120-per-month), August 2026; Perplexity, [Comet browsing privacy](https://comet-help.perplexity.ai/en/articles/12867356-browsing-privacy-safety).
- [OpenClaw documentation](https://docs.openclaw.ai/) and [security page](https://docs.openclaw.ai/security); [OpenClaw on Wikipedia](https://en.wikipedia.org/wiki/OpenClaw); [OpenClaw 2.0 review](https://www.therundown.ai/tools/openclaw-2-0); [the January 2026 incidents](https://adversa.ai/blog/openclaw-security-101-vulnerabilities-hardening-2026/).
- Confidential compute: AWS, [Nitro Enclaves and KMS](https://docs.aws.amazon.com/enclaves/latest/user/connect-enclave-kms.html); Trail of Bits, [notes on the KMS integration](https://blog.trailofbits.com/2026/08/05/a-few-notes-on-aws-nitro-enclaves-kms-integration/), 5 August 2026; Google, [Confidential Space](https://docs.cloud.google.com/confidential-computing/confidential-space/docs/confidential-space-overview) and [what's new, June 2026](https://cloud.google.com/blog/products/identity-security/verifiable-trust-in-the-ai-era-whats-new-in-confidential-computing); Microsoft, [Secure Key Release](https://learn.microsoft.com/en-us/azure/confidential-computing/concept-skr-attestation) and [confidential VMs with H100](https://techcommunity.microsoft.com/blog/azureconfidentialcomputingblog/general-availability-azure-confidential-vms-with-nvidia-h100-tensor-core-gpus/4242644); NVIDIA, [confidential inference](https://developer.nvidia.com/blog/enabling-private-high-performance-production-ai-inference-with-nvidia-confidential-computing/); Cohere, [confidential inference](https://venturebeat.com/data/coheres-model-vault-now-encrypts-ai-inference-so-even-cohere-cannot-see-enterprise-customers-data), 16 September 2026; the physical attacks, [WireTap](https://thehackernews.com/2025/10/new-wiretap-attack-extracts-intel-sgx.html), [Battering RAM](https://batteringram.eu/) and [TEE.fail](https://thehackernews.com/2025/10/new-teefail-side-channel-attack.html), 2025.
- Browser compute: [WebGPU in the major browsers](https://web.dev/blog/webgpu-supported-major-browsers), November 2025; [WebLLM](https://arxiv.org/html/2412.15803v2); [Transformers.js v4](https://huggingface.co/blog/transformersjs-v4), February 2026; [Chrome Prompt API](https://developer.chrome.com/docs/ai/prompt-api).
- Regulation: [GDPR Articles 25](https://gdpr-info.eu/art-25-gdpr/), [28](https://gdpr-info.eu/art-28-gdpr/) and [32](https://gdpr-info.eu/art-32-gdpr/); ICO, [Tech Futures: Agentic AI](https://ico.org.uk/about-the-ico/research-reports-impact-and-evaluation/research-and-reports/technology-and-innovation/tech-horizons-and-ico-tech-futures/ico-tech-futures-agentic-ai/), 8 January 2026; CNIL, [note on agentic AI](https://www.insideprivacy.com/artificial-intelligence/french-cnil-publishes-note-on-agentic-ai-and-data-protection/), 20 July 2026; FTC chairman at Reuters NEXT, [25 September 2026](https://kfgo.com/2026/09/25/reuters-next-ftc-chair-pushes-back-on-treating-ai-agents-as-independent-actors/).
- On this site: [RiskMandate's Agent Behaviour Policy](https://riskmandate.ai/abp.html); [the security model](../security/index.md); [Limitations](../docs/limitations.md).

*Drafted from a voice memo by Dinis Cruz, who is the author of the argument and the person with editorial responsibility, by agent@riskmandate.ai (Claude Fable 5.1, claude-fable-5-1) in the sgit.ai site session, on 6 October 2026. Product facts were gathered on that date from the vendors' own pages and from the press reports listed, and each is marked in the text as a vendor statement or a report; two research passes, one over the external sources and one over this site's own documentation, preceded the writing. The figures are infographics and design sketches with no live data; the landscape positions are approximate. Nothing in the design section is built, and the status section says what is.*

*© 2026 Dinis Cruz. This article's own text is licensed under [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/). You're free to share and adapt it, as long as you give credit. Quoted material and linked sources keep their own licences.*

## Threads

Agents & policyVaults & method[This article as a graph →](graphs.md#a-personal-agent-that-keeps-your-secrets)

### Builds on

- [The agent team as it runs: one person, twelve agents, encrypted vaults, and a mailbox nobody sends from](the-agent-team-as-it-runs.md) Twelve agents on dedicated accounts, encrypted vaults as the only memory, messages as files, a folder per person, and a mailbox nobody sends from.
- [Footprint and blast radius: what the agent actually did, and what it would have cost](footprint-and-blast-radius.md) Footprint is what an agent actually did, read afterwards from logs and vault history; blast radius is what a row of its reach would cost the business today.
- [The ultimate insider: agents, the infrastructure that cannot hold them, and risk management that cannot keep up](ultimate-insider-three-collisions.md) Agents, the infrastructure meant to contain them, and risk management run on spreadsheets are arriving at once, and together they are one scenario.
- [Git for things you cannot put on GitHub](what-sgit-is.md) sgit is git for files you cannot put on GitHub: encrypted before they leave your machine, versioned like git, stored where the server cannot read a byte.
- [Six agents, one inbox: what a real multi-agent setup taught me about access policies](six-agents-one-inbox.md) An access policy for an agent is only as real as its worst row: every rule in a real six-agent setup, graded by how it is enforced today.
- [The identity we wanted to give the agents: a week of design, the line in Google's terms, and why login plus secrets is still too hard](the-identity-we-wanted-to-give-the-agents.md) A week of designing identities for agents and users met Google's terms; what survived is a passkey-unlocked keyring and a gap nobody sells.
- [Memory is not a spectator sport: how a web of open sites, graphs and vaults became the memory for sessions like this one](memory-is-not-a-spectator-sport.md) Agentic memory as context management: many published, fractal, provenance-carrying memories rather than one store, shown in the session that wrote the article.
- [Fractal Semantic Graphs: everything connects to everything, and nobody has to share a schema](introducing-fractal-semantic-graphs.md) A fractal semantic graph has no privileged level and no single schema: each world keeps its own vocabulary and connects to others through named edges.
- [Before you give an agent a connector, give the connector a twin](connector-twin-before-you-deploy-an-agent.md) An agent with a Gmail or Calendar connector can do things the platform cannot undo; a journal of every call, replayed, shows what it did and what can go back.

### Continued by

- [The agent team as it runs: one person, twelve agents, encrypted vaults, and a mailbox nobody sends from](the-agent-team-as-it-runs.md) Twelve agents on dedicated accounts, encrypted vaults as the only memory, messages as files, a folder per person, and a mailbox nobody sends from.
- [The deck I could not download: an author-first home for presentations, as a business plan somebody else can build](the-deck-i-could-not-download.md) One download offered as a subscription, an author paid nothing, and a design for the service the author would have chosen: vaults, keys, seven roles, 85% to the author.

[All articles](index.md) · [All graphs](graphs.md)

**Get new articles by email.** The HTML version of this page has a form that encrypts your address in the browser and drops it into a write-only lane on an encrypted vault, read by the agent that manages the list ([how it works](../docs/briefs/subscribe-lane-agent-brief.md)). Or email [agent@riskmandate.ai](mailto:agent@riskmandate.ai?subject=Subscribe%3A%20sgit.ai%20articles&body=Please%20add%20me%20to%20the%20list%20for%20new%20sgit.ai%20articles.) with the subject "Subscribe: sgit.ai articles".

[← All articles](index.md)


---

*[Site index for agents](../llms.txt) · [HTML version](https://sgit.ai/articles/a-personal-agent-that-keeps-your-secrets.html)*
