Trust through precision

Clear controls. Honest boundaries. No magic-language security.

Tek products are being built for consequential work. We describe the control each surface actually implements, identify what leaves the system, and label product readiness instead of turning architecture into a blanket promise.

Scoped identity and access

Products use organization, project, entity, API-key, agent, and tool controls where supported. Access claims remain specific to the surface implementing them.

Approval before consequence

Sensitive agent actions can require human approval. Unattended work must be explicitly authorized for the tools it is allowed to use.

Local-first where it is real

The Agent Hub runtime, state, memory, and execution control live on the Mac. Configured models and integrations may receive the data required to perform their work.

Remote access with boundaries

Mobile connects to the Mac Gateway through Relay. Message payloads are encrypted between endpoints; Relay still handles necessary routing and connection metadata.

Email is untrusted input

TekMail applies policy, scanning, approval, quarantine, and allowlist controls. These are defense-in-depth—not a guarantee against every malicious message or delivery failure.

Readiness is part of the trust model.

Tek Agents, TekPartner Workspace, and TekMail are in active development. We are using private demos and design-partner conversations while launch gates are completed. The Agent Hub stack is an internal reference system for custom work, not a generally available product.

  • No unverified compliance or certification claims
  • No claim that nothing ever leaves the device
  • No promise of unrestricted or error-free autonomy
  • Synthetic demo data labeled as synthetic
  • Release and host requirements stated before deployment
  • Production responsibilities agreed per engagement