Nothing leaves without your say-so.
Every action is checked before it runs, held for your approval if it touches anyone else, and written to a log you can replay.
Sarah asked about the Henderson place — can you get back to her?
- Read your thread with Sarah Chen. She asked about Henderson Ave on Sunday and you never replied.
- Checked the listing. Still active, and the price dropped $15k on Friday.
- Pulled three comps within half a mile that closed this month.
- Looked at your calendar. Thursday 2pm and Saturday 11am are open.
- Wrote her a reply with the comps and both times.
“Hi Sarah — Henderson just came down $15k. I pulled three comps nearby, all closed under ask. I have Thursday 2pm or Saturday 11am free if you want to walk it.”
Sent to Sarah. Booked provisionally for Thursday 2pm, held on your calendar until she confirms.
A policy layer
Every action is checked against your rules before it runs. Sending mail, moving money, touching a calendar: you decide which need a human and which do not.
Approve in the thread
Anything held for approval arrives as a message. Reply to approve, reply to change it, or say nothing and it never happens.
Replay anything
Every action is logged with what it did, what it touched, and why. Open any one and step back through the reasoning.
A day, on the record.
This is what your log looks like. Held actions wait for you. Blocked ones never ran. Open a row to read the reasoning.
Reading your own message threads is always allowed under your default policy. No approval needed, and it is still written to the log.
Read-only lookup against the MLS connection you authorised at setup. Nothing was written or shared.
Your policy holds every outbound message to a client for approval. The draft sat in the thread until you replied “send”.
Released by you at 07:44 with a one-word reply. The exact text that was sent is stored against this entry.
Calendar holds on your own diary are pre-approved. Invitations to other people are not — that is a separate rule.
Anything that moves money is blocked outright, not held. There is no approval flow for this — the action can never run.
Writes to your own CRM are allowed within the bundle scope. Each field change is recorded individually and can be reversed.
Messages to you are never held — only messages to other people are. This one went straight to your thread.
Open any row to see why the agent did it.
Your agent runs in its own container. Your data isn't pooled and isn't used to train anything. You can read every action it has ever taken — and revoke the whole thing in one message.
Where we are on certifications.
Honest about timelines. We're a small team working toward certifications methodically, and this is the roadmap.
Email security@wrasse.ai for current status, our security review materials, or a copy of our data-processing agreement.
Found something? Tell us.
Send security issues to security@wrasse.ai. Please include reproduction steps, impact, and any proof-of-concept code. We acknowledge within 24 hours, triage within 72 hours, and credit researchers in our public disclosure log unless you'd rather stay anonymous. The bug bounty opens publicly in Month 3; private payouts now.
Please do not test against accounts that aren't yours, exfiltrate any data, or run automated scanning that affects service availability for other users. Everything else is on the table.
Earn the queue.
We open one bundle at a time. Reserving tells us which is next — and puts you in the first group when it is.
Reserve accessNo card, no call. One email when your bundle opens.