Connecting your analytics, billing and app data to anything means trusting it with passwords and keys. So here's the plain version of how we handle yours — what's protected, what the AI can and can't touch, and how to switch it off the moment you want to.
Read-only access is all we ask for. You can disconnect any source in one click.
Four promises
The AI never sees them
Our servers hold your keys and use them to fetch data. The AI only receives the data that comes back — never the key, in the question, the answer, or anywhere in between.
Locked, not lying around
Every key is encrypted with the same standard banks and browsers use, and the code that unlocks it is kept somewhere separate. Even someone holding a copy of our database would have nothing usable.
Off the moment you say so
Disconnect a source and it stops working immediately — there's no copy sitting in a cache somewhere to keep going. Delete it and the stored key is destroyed outright.
Read-only, so nothing can break
We ask for view-only access wherever a tool offers it. A read-only key can look at your data but cannot change or delete a single thing — so even a worst case stays a worst case you can live with.
How a question actually works
Step one
You ask a question
The AI works out which of your tools it needs to look at. It knows the tool's name and what to ask it — nothing more.
Step two · our servers
We fetch the data with your key
Your key is unlocked, used for that one request, and forgotten again. This all happens on our side — the AI isn't part of it.
Step three
The AI reads the numbers
It gets the data back and explains what it means. Anything that looks like a password or key is stripped out before it arrives, as a second line of defence.
✕Put a key of yours into an AI prompt
✕Store a key as plain readable text, anywhere
✕Write one into a log file or an audit record
✕Let the AI change, delete or spend anything on its own
✕Let another customer's account reach your data
✓Which tools you connect, one at a time
✓How much access each one gets — read-only is enough
✓Disconnecting any of them, instantly, without asking us
✓Seeing a full record of every connection change
✓Rotating the key at the source, any time you like
Straight answers
Could the AI leak my key by accident?
It can't leak what it never had. The key is used before the AI is involved, and a second filter strips anything key-shaped out of what it does receive. Two separate things would have to fail at once.
Can BonnieOS change things in my tools?
Not unless you deliberately turn on an action — like posting a report to Slack or creating a task. Everything else is view-only by design, and actions like those stay behind your approval.
What if I want out?
Disconnect a source and access stops on the spot. For total peace of mind you can also rotate the key in the tool itself — that's the switch we can never touch, and it's always yours.
Can anyone else see my data?
No. Each customer's connections are walled off at the database level, not just in our app code, so there's no path from someone else's account to yours even if something went wrong.
Do you keep a record of changes?
Yes — every connect, test, disconnect and delete is logged with who did it and when. The record never contains the key itself, only what happened to it.
Are you certified or audited?
Not yet, and we'd rather say so than imply otherwise. What exists today is the architecture on this page, which we're happy to walk through in as much detail as you want.
Reviewing us on behalf of a security team?
There's a longer version of this page with the encryption details, the code paths, the database policies and the exact files each claim lives in — written for someone whose job is to poke holes in it.
Still have a question? Ask us directly — we'd rather answer something specific than have you take our word for any of this.
You can disconnect it in one click. Free while we're in early access.