Scoped, not shared
Each connection is an OAuth token scoped to one tool, held per company and reachable only by the agents whose mandate names it. Two agents cannot borrow each other’s access.
Autonomy is only worth having if it is bounded. Everything on this page is on by default, enforced by the platform rather than by the model, and cannot be switched off by an agent — including by an agent you asked to switch it off.
JURISDICTION
Zuger Technologies OÜ is the contracting entity, the data controller and the seller of record. Estonian law governs, the GDPR applies in full, and your data is stored in the European Union.
CONTROL
Filings, payments, contracts and anything customer-facing stop at an approval. Bank connections are read-only, through a licensed open-banking provider — Zuger never holds your bank credentials and has no way to move money. Thresholds are yours, per agent, per amount, per counterparty, and an agent cannot read or raise its own.
EVIDENCE
Every page opened, field typed and file touched is written to an append-only log with the reasoning that led to it. Export it for your auditor in one click.
CREDENTIALS
Every connection is a scoped OAuth token, encrypted at rest and decrypted only inside the worker that uses it. An agent reaches only the connections its mandate names. Revoke one and it stops working mid-run, cleanly, without touching the others. We never hold your passwords.
DATA
| Question | Answer |
|---|---|
| Where is my data stored? | In the European Union. Region-pinned per account, not merely labelled. Swiss residency is on the roadmap and will be offered when the storage actually honours it. |
| Who can read it? | Your agents, and the people you invite. Zuger staff access requires a named support ticket from you, is time-boxed, and appears in your audit log. |
| Are my credentials stored in plaintext? | No. Connections are scoped OAuth tokens, encrypted at rest with per-tenant keys and decrypted only inside the worker that uses them. We never hold a bank password at all — transaction data arrives read-only through a licensed open-banking provider. |
| Do you train models on my company’s data? | No. The model providers we use are engaged on commercial terms that forbid training on customer data and require zero retention beyond the request. Where a provider cannot offer that, we do not use it. The commitment is contractual — in our terms with them and in the DPA with you — not a toggle in a settings screen. |
| What happens when I leave? | Export everything — documents, logs, memory, routines — in open formats. Deletion completes within 30 days and is itself logged. Audit and accounting records are retained for seven years under Estonian law, detached from your profile. |
| Which subprocessors are involved? | Listed, with purpose and location, on the subprocessors page. You are notified 30 days before any addition. |
CONNECTED TOOLS
Rendered from the connector registry the product runs on: the same list, the same scopes. Every connector is read-only by type; a write scope cannot be registered. If a connection drops, the agent stops and asks you to reconnect. It never guesses.
Säntis · reading XeroRead bank transactions and invoices, so Säntis can reconcile them.
Tap a tool to see exactly what it may read, and why. A write scope cannot be registered: the lock is a property of the type, not a promise.
THE BOUNDARY
Least privilege is the reason a compromised connection stays one connection rather than becoming a compromised company.
Each connection is an OAuth token scoped to one tool, held per company and reachable only by the agents whose mandate names it. Two agents cannot borrow each other’s access.
Bank feeds are read-only, through a licensed open-banking provider. There is no payment initiation in the product, so there is nothing to compromise into a transfer.
Tokens are encrypted at rest and decrypted only inside the worker that uses them. They never reach a model prompt, a run trace, a log or an export.
Text an agent reads in a web page, an email or a document is never an instruction. Only you can change a mandate, and anything derived from fetched content that crosses a threshold goes to approval regardless of policy.
If a capability would need your password typed into a website, we do not build it. That is a deliberate limit on what the product can promise.
One button stops every agent in your company, mid-run, and revokes every live connection.
BERNINA
Every Run is checked before, during and after. Bernina scans your documents for hidden instructions, holds every agent to read-only, and stops anything leaving that shouldn't. You never meet Bernina. It's why the rest can be trusted.
BERNINA · GUARDIAN LAYER
Not on the roster. Not for hire. Every Run passes through it.
Documents, emails and connector data are read for injected instructions before any agent sees them.
Every tool call is checked against the agent's read-only allowlist. A write, send or delete attempt stops the Run.
Outputs are scanned for secrets, card numbers, IDs and data from another company before they are stored or shown.
Nothing to report. 214 documents read, 61 tool calls, one VAT return prepared.
Bernina runs on every plan, including Free, and never counts against your Runs.
COMPLIANCE
We would rather tell you what is in progress than imply a badge we do not have yet.
| Item | Status |
|---|---|
| GDPR — DPA, SCCs, record of processing | Available today |
| Swiss FADP | Available today |
| Data residency — EU | Available today |
| Data residency — Switzerland | On the roadmap · offered when the storage honours it |
| Audit log export | Available today |
| SOC 2 Type I | In progress · target Q4 2026 |
| SOC 2 Type II | Planned · 2027 |
| ISO 27001 | Planned · 2027 |
| Penetration test — third party | Annual · first report on request |
IF SOMETHING GOES WRONG
security@zuger.ai — acknowledged within one working day. We do not take legal action against good-faith research.
Affected customers are told within 72 hours with what happened, what data was involved and what we changed. Every incident gets a written timeline.
If an agent does something you did not expect, the log shows what it did and why. Send us the run id and we will explain it.
STANDING DISCLAIMER
Zuger is not a law firm, an accountancy practice or a tax agent, and does not provide regulated advice. Agents prepare work; filing, signing and paying stay with you. Where an agent prepares a filing, a return or a contract, the document is yours to check, sign and submit. Nothing an agent produces is legal, tax or accounting advice, and no agent is authorised to act as your agent before a registry, a tax authority or a bank.
Terms, privacy, the DPA and the subprocessor list are all one click away — no sales call required.
Log in to pick up where the agents left off
Lost your passkey?Don’t have an account? Create account
By continuing you agree to our Terms & Privacy Policy
Free to start · No card
Already have an account? Log in
By continuing you agree to our Terms & Privacy Policy
If can be used, a link is on its way.
Open it on the device you want to sign in with — your phone, most likely. It works once, expires in a few hours, and can only create a passkey: it cannot read anything or approve anything.