NewWe just launched Attention! Try it free.
Righthand

Built to be trusted with your work.

A Righthand works across your accounts and conversations.
That merits specific controls and clear boundaries.

Your data is yours.

We do not sell it or share it for advertising.

No model training.

User inputs and outputs are not used to train models.

Encrypted in transit and at rest.

TLS 1.2 or higher protects data in transit. Stored customer data is encrypted at rest.

You stay in control.

Connections are optional. External communications can be configured to run, ask first, or stay off.

Your data

Righthand needs context to help you. We protect that context.

Private by policy

We do not sell user data or share it for advertising. User inputs and outputs are not used to train models.

Stored with purpose

A Righthand maintains memory and operational context so it can continue the job across conversations. Customer data is hosted in the United States and stays in secured production systems, never on employee devices.

Deletion on request

You can ask us to delete your data. We delete your data. Period.

Infrastructure

Security is built into the boundaries between your Righthand, its workspace, your tools, and our services.

Encryption

Data in transit is protected with TLS 1.2 or higher. Stored customer data is encrypted at rest, and sensitive APC-managed credential paths use AES-256-GCM encryption.

Isolated workspaces

Each Righthand runs in an isolated cloud workspace with persona-scoped runtime state. Database access is scoped to your team and your Righthand.

Scoped credentials

Credentials are kept out of model context, and tool calls use tightly scoped tokens.

Control

A useful Righthand takes actions in the real world. The important question is which actions it can take, under whose identity, and when it asks for permission.

Ask before acting

External communications can be configured as Yes, Ask, or No. When approval is required, Righthand must receive authorization before the provider action runs.

Connections are optional

You choose which services to connect and which Righthand can use them. Connections can be disconnected when they are no longer needed.

Layered defenses

Identity and source context travel with incoming messages. Untrusted content is treated as data, not authority, while permissions and approvals limit what manipulated content can do.

Operations

Protection also depends on how the service is operated, observed, reviewed, and recovered.

Monitored around the clock

Production services are monitored 24/7 by humans and agents. All events carry trace and Righthand IDs so incidents can be investigated and audited with certainty.

Restricted production access

Production access requires employee SSO and MFA, uses short-lived sessions, and follows least-privilege and just-in-time access practices with periodic review.

Recovery and review

Righthand maintains recoverable filesystem backups, guarded restore flows, and automated recovery checks. We also run regular vulnerability scanning.

Common questions, answered.

Here are the details teams ask for most often.

What does Righthand store?

Righthand stores the context needed to maintain memory and perform ongoing work. Depending on how you use it, that can include messages, files, thoughts, reminders, connection metadata, communications records, operational logs, and backups.

Is my data used to train AI models?

No. User inputs and outputs are not used to train our models or our model providers’ generalized models.

Can I control what my Righthand is allowed to do?

Yes. Connections are assigned explicitly, and external communications can be configured to run, ask for approval, or stay off. Righthands can also operate autonomously where you choose to allow it.

Can I disconnect an integration?

Yes. Integrations are optional and can be disconnected through Righthand or the connected provider. Authentication methods vary by provider, so revocation behavior can vary too.

Can I request deletion of my data?

Yes. Email our team to request deletion. We will carry out your request.

Can my team request a security review?

Yes. We can answer a security questionnaire, share the documentation we maintain, or walk through your requirements directly with your team.

Bring us your security questions.

We can share our documentation, answer questions, or walk your team through the controls behind Righthand.