Trust posture

Power you can see, scope, and review.

Fae keeps context visible, capabilities scoped, sensitive actions gated, and results reviewable. You can see what it knows, what it can do, and what happened.

Boundary

Your machine is the default boundary.

Project state, settings, artifacts, memory, and diagnostics stay local by default. External services enter only when you choose them.

T-01

Cloud access is a choice

Controlled per provider

Local context stays out of cloud requests unless enabled for that provider. One provider's permission never carries to another.

T-02

Managed usage stays visible

Balances · limits · recovery

Profile shows managed balances, limits, capacity pauses, and recovery choices.

T-03

Diagnostics leave only when you send them

Explicit support export

Support bundles contain only the diagnostic information you choose to export. Fae does not silently upload project content, memory, browser history, or local activity records.

Approvals

Sensitive actions pause for a decision.

Pending approvals, active permissions, recovery options, and unavailable capabilities stay visible and separate from the answer.

T-04

Actions ask first

One consent layer

Sensitive file, command, browser, cloud, research, and recovery actions use one consistent approval flow.

T-05

Browser control is paired and armed

Deliberate · expiring · separate

A short-lived code pairs the extension. Deep control is armed deliberately, expires automatically, and stays separate from web search.

T-06

Connected tools remain governed

MCP with explicit authority

MCP servers are approved by exact command or URL, scanned for injection risk, and governed like native tools. Suspicious tool output is quarantined rather than trusted.

Review

Every meaningful action leaves a record.

Significant actions, changes, checks, approvals, browser activity, and restore points stay together for review.

Evidence

Results carry their supporting evidence.

Planning, execution, approvals, and completed checks remain attached to the result.

Fae Code mode showing a completed bug-fix run, scoped project files, local file access, and process logger receipts.
A completed run with project files, access state, activity history, and supporting evidence in one frame.

Memory & recovery

Continuity should stay accountable.

Working memory keeps its source, confidence, lifecycle, and scope so remembered context remains open to correction.

T-07

Remembered context keeps its source

Provenance on every record

Memory records where a fact came from, whether it was inferred, and how strongly it should guide future work.

T-08

Interrupted work can recover

State preserved · options visible

Capacity limits, stalls, conflicts, and errors become recoverable states with explicit next actions.

T-09

Changes keep a way back

Restore — or a clear limitation

Supported writes capture restore or undo state first. Any recovery limitation is shown before changes continue.

Private beta

Test Fae on work where control matters.

Bring a workflow where permissions, approvals, review, and recovery matter.