Trust

Evidence instead of badges.

We have no certificates to show. What we can do is say exactly what it does, what it does not do, and where that lives. This page moves with the code; every change is in the changelog.

What we are, and what we are not yet

New, built in the Netherlands. No customers yet. No SOC 2 or ISO certificate: we do not have one and do not pretend to. What we can show is below, with the source of every line.

What it does not do in this version

Every line is true of the code on the day this page was built, and names where that is so.

  • During a shadow week nothing reaches your customers. A reply to a customer needs stage 2; a shadow week runs at stage 0, which posts nothing.

    autonomy_service.may_post · autonomy_settings (stage 0: post nothing)
  • When you connect Shopify, Maximal requests read_orders and read_products only. A token you paste yourself can carry more rights; then what you granted applies.

    shopify_oauth.SHOPIFY_SCOPES
  • The read path the model drives refuses any request to Shopify that is not a read, whatever the token permits.

    ShopifyShop._execute
  • The amount compared with your limit comes from the order, never from the email. Where the model and the order disagree, the larger figure counts.

    agent/tools.compute_impact · propose_action
  • It does not change a delivery address: that action is switched off in this version, whoever asks.

    shop/resolver: address_resolver is not set
  • It has never carried out a refund, a cancellation or a return. It proposes them; carrying them out is off by default.

    COMMERCE_WRITES_ENABLED and EXECUTION_ENABLED are off by default

Where your data goes, today

Taken from our sub-processor register. What reads badly is in it too: leaving it out would make the list incomplete.

PartyFor whatWhereWhen
Anthropic PBCThe language model: reads the conversation and order data and writes a draft and a proposal.Wherever the Anthropic API terminates. This version pins no region and has no EU endpoint or zero-retention agreement.Always
Hosting and databaseRuns the application and stores all data.Not chosen yet. It will be set in configuration and listed here before the first shadow week.Always
Logs and metricsErrors and performance. Personal data is filtered out before anything is written.No destination configured yet.Always
Your helpdesk (Trengo, Zendesk, Gorgias or Chatwoot)Source of the conversations and, from stage 1, where drafts arrive as internal notes.That helpdesk’s infrastructure. For Trengo and Zendesk this version holds no statement about the region.If you connect that helpdesk
Your store (Shopify or WooCommerce)Source of the order state. Read-only.Shopify: their infrastructure. WooCommerce: wherever you host WordPress.If you connect your store

Source: the register in the code, read on 3 Oct 2026.

What we commit to

With a status. A missed commitment stays here, with the reason.

  • OpenInference pinned to the EU, before the first ticket of a shadow week.
  • OpenHosting with a named EU provider, listed on this page, before the first ticket of a shadow week.
  • OpenA signed processing agreement with you, before the first ticket.
  • OpenCompany details with KVK number on this site, before the first shadow week.
  • OpenThe page at the end of every shadow week lists what it got wrong.

What we keep

  • You set retention periods yourself, per account.
  • Every decision has a record: what it read, which rule and which version, what it proposed, which amount.
  • The record is a hash chain: an altered or deleted row shows, even after personal data has been erased.
  • Access tokens for your store and helpdesk are stored encrypted (Fernet, with a salt per value).
  • A customer’s request for access or erasure can be carried out per person.

What is not finished

From the same list the code keeps. What is here, we know; what we do not know is not here.

  • Breaches: the code notices one kind automatically, an altered or deleted row in the record. A leaked password or a misdirected export is only noticed when a person sees it and records it. There is no written breach runbook yet.
  • A notice about a new sub-processor that cannot be delivered is reported, not re-sent automatically.
  • No SOC 2, no ISO 27001, no ISO 42001.
  • No processing agreement is published yet; we sign one per shadow week, before the first ticket.

The AI Act, article 50

Since 2 August 2026, someone talking to an AI system has to be told it is AI. It applies to systems that communicate with people directly.

In a shadow week, and at stage 1, Maximal writes drafts and a person sends every reply. Whether the disclosure duty already applies then, and what it looks like from stage 2, is an open legal question we have written up for a lawyer. Until it is answered, we call it open.

There is no "AI Act compliant" certificate, so we do not claim one.

Security, briefly

  • The model never calls your systems directly. It picks from a fixed set of tools with strict schemas; an unknown tool is blocked and recorded.
  • The console screens load nothing from other domains and allow no inline scripts (a strict Content Security Policy).
  • This website sets no cookies, uses no trackers and makes no requests to other domains.

An address for security reports follows together with our contact address.

Where this comes from

Everything on this page comes from the code or our status document, not from a brochure. When something stops being true we change it, and the correction, with the old wording struck through, is in the changelog.

To the changelog