Trust posture
Power you can see, scope, and review.
Fae keeps context visible, capabilities scoped, sensitive actions gated, and results reviewable. You can see what it knows, what it can do, and what happened.
Boundary
Your machine is the default boundary.
Project state, settings, artifacts, memory, and diagnostics stay local by default. External services enter only when you choose them.
Cloud access is a choice
Controlled per providerLocal context stays out of cloud requests unless enabled for that provider. One provider's permission never carries to another.
Managed usage stays visible
Balances · limits · recoveryProfile shows managed balances, limits, capacity pauses, and recovery choices.
Diagnostics leave only when you send them
Explicit support exportSupport bundles contain only the diagnostic information you choose to export. Fae does not silently upload project content, memory, browser history, or local activity records.
Approvals
Sensitive actions pause for a decision.
Pending approvals, active permissions, recovery options, and unavailable capabilities stay visible and separate from the answer.
Actions ask first
One consent layerSensitive file, command, browser, cloud, research, and recovery actions use one consistent approval flow.
Browser control is paired and armed
Deliberate · expiring · separateA short-lived code pairs the extension. Deep control is armed deliberately, expires automatically, and stays separate from web search.
Connected tools remain governed
MCP with explicit authorityMCP servers are approved by exact command or URL, scanned for injection risk, and governed like native tools. Suspicious tool output is quarantined rather than trusted.
Review
Every meaningful action leaves a record.
Significant actions, changes, checks, approvals, browser activity, and restore points stay together for review.
Evidence
Results carry their supporting evidence.
Planning, execution, approvals, and completed checks remain attached to the result.
Memory & recovery
Continuity should stay accountable.
Working memory keeps its source, confidence, lifecycle, and scope so remembered context remains open to correction.
Remembered context keeps its source
Provenance on every recordMemory records where a fact came from, whether it was inferred, and how strongly it should guide future work.
Interrupted work can recover
State preserved · options visibleCapacity limits, stalls, conflicts, and errors become recoverable states with explicit next actions.
Changes keep a way back
Restore — or a clear limitationSupported writes capture restore or undo state first. Any recovery limitation is shown before changes continue.
Private beta
Test Fae on work where control matters.
Bring a workflow where permissions, approvals, review, and recovery matter.