TRUST

An agent near your bank
had better be Swiss about it.

Autonomy is only worth having if it is bounded. Everything on this page is on by default, enforced by the platform rather than by the model, and cannot be switched off by an agent — including by an agent you asked to switch it off.

  • JURISDICTION

    Tallinn, Estonia

    Zuger Technologies OÜ is the contracting entity, the data controller and the seller of record. Estonian law governs, the GDPR applies in full, and your data is stored in the European Union.

  • CONTROL

    Agents prepare, you sign

    Filings, payments, contracts and anything customer-facing stop at an approval. Bank connections are read-only, through a licensed open-banking provider — Zuger never holds your bank credentials and has no way to move money. Thresholds are yours, per agent, per amount, per counterparty, and an agent cannot read or raise its own.

  • EVIDENCE

    Everything is on the record

    Every page opened, field typed and file touched is written to an append-only log with the reasoning that led to it. Export it for your auditor in one click.

  • CREDENTIALS

    Scoped tokens, revocable

    Every connection is a scoped OAuth token, encrypted at rest and decrypted only inside the worker that uses it. An agent reaches only the connections its mandate names. Revoke one and it stops working mid-run, cleanly, without touching the others. We never hold your passwords.

DATA

Where it lives, who touches it,
and what we will not do with it.

QuestionAnswer
Where is my data stored?In the European Union. Region-pinned per account, not merely labelled. Swiss residency is on the roadmap and will be offered when the storage actually honours it.
Who can read it?Your agents, and the people you invite. Zuger staff access requires a named support ticket from you, is time-boxed, and appears in your audit log.
Are my credentials stored in plaintext?No. Connections are scoped OAuth tokens, encrypted at rest with per-tenant keys and decrypted only inside the worker that uses them. We never hold a bank password at all — transaction data arrives read-only through a licensed open-banking provider.
Do you train models on my company’s data?No. The model providers we use are engaged on commercial terms that forbid training on customer data and require zero retention beyond the request. Where a provider cannot offer that, we do not use it. The commitment is contractual — in our terms with them and in the DPA with you — not a toggle in a settings screen.
What happens when I leave?Export everything — documents, logs, memory, routines — in open formats. Deletion completes within 30 days and is itself logged. Audit and accounting records are retained for seven years under Estonian law, detached from your profile.
Which subprocessors are involved?Listed, with purpose and location, on the subprocessors page. You are notified 30 days before any addition.

CONNECTED TOOLS

What can be connected,
and what each one may read.

Rendered from the connector registry the product runs on: the same list, the same scopes. Every connector is read-only by type; a write scope cannot be registered. If a connection drops, the agent stops and asks you to reconnect. It never guesses.

12 live2 under contractAll read-only by typeregistry exported 2026-09-12

Säntis · reading XeroRead bank transactions and invoices, so Säntis can reconcile them.

Tap a tool to see exactly what it may read, and why. A write scope cannot be registered: the lock is a property of the type, not a promise.

THE BOUNDARY

One token, one tool,
one agent.

Least privilege is the reason a compromised connection stays one connection rather than becoming a compromised company.

Scoped, not shared

Each connection is an OAuth token scoped to one tool, held per company and reachable only by the agents whose mandate names it. Two agents cannot borrow each other’s access.

Read-only where it matters

Bank feeds are read-only, through a licensed open-banking provider. There is no payment initiation in the product, so there is nothing to compromise into a transfer.

Encrypted, and never echoed

Tokens are encrypted at rest and decrypted only inside the worker that uses them. They never reach a model prompt, a run trace, a log or an export.

Injection is treated as data

Text an agent reads in a web page, an email or a document is never an instruction. Only you can change a mandate, and anything derived from fetched content that crosses a threshold goes to approval regardless of policy.

No stored logins, no browser driving

If a capability would need your password typed into a website, we do not build it. That is a deliberate limit on what the product can promise.

Kill switch

One button stops every agent in your company, mid-run, and revokes every live connection.

BERNINA

Bernina — the standing guard.

Every Run is checked before, during and after. Bernina scans your documents for hidden instructions, holds every agent to read-only, and stops anything leaving that shouldn't. You never meet Bernina. It's why the rest can be trusted.

BERNINA · GUARDIAN LAYER

Not on the roster. Not for hire. Every Run passes through it.

BEFORE

Documents, emails and connector data are read for injected instructions before any agent sees them.

DURING

Every tool call is checked against the agent's read-only allowlist. A write, send or delete attempt stops the Run.

AFTER

Outputs are scanned for secrets, card numbers, IDs and data from another company before they are stored or shown.

Month-end close · Säntis

Nothing to report. 214 documents read, 61 tool calls, one VAT return prepared.

Bernina runs on every plan, including Free, and never counts against your Runs.

COMPLIANCE

Where we are,
said plainly.

We would rather tell you what is in progress than imply a badge we do not have yet.

ItemStatus
GDPR — DPA, SCCs, record of processingAvailable today
Swiss FADPAvailable today
Data residency — EUAvailable today
Data residency — SwitzerlandOn the roadmap · offered when the storage honours it
Audit log exportAvailable today
SOC 2 Type IIn progress · target Q4 2026
SOC 2 Type IIPlanned · 2027
ISO 27001Planned · 2027
Penetration test — third partyAnnual · first report on request

IF SOMETHING GOES WRONG

Report it, and hear back
the same working day.

Security reports

security@zuger.ai — acknowledged within one working day. We do not take legal action against good-faith research.

Incidents

Affected customers are told within 72 hours with what happened, what data was involved and what we changed. Every incident gets a written timeline.

Your own agents

If an agent does something you did not expect, the log shows what it did and why. Send us the run id and we will explain it.

Free plan · No card

Read the fine print
before you trust us.

Terms, privacy, the DPA and the subprocessor list are all one click away — no sales call required.