Skip to content

Autonomous.Not unsupervised.

Ray does real work on its own. Anything that touches your tools waits for your approval, and you can check exactly how your data is held.

Nothing sensitive moves without your Approve.

Ray drafts the whole thing and shows you exactly what will happen: who it gets sent to and what it says, word for word. One click sends it, one click stops it.

  • Approve or decline anything sensitive
  • The card shows the exact content, verbatim
  • No setting turns approvals off. It's architecture.

RayApp9:14 AM

Send Jonas the follow-up on the March pilot invoice.

Send email

To
jonas@northwind.co
Subject
March pilot invoice
Hi Jonas, following up on the March pilot invoice (#2041). It's still showing unpaid on our side. Could you take a look this week? Happy to resend it if it got buried.

Security you can check.

Not a trust-us page. Every line here is a mechanism you can point to, not a promise we make.

Your workspace is sealed off from every other.

11 tables · 8 attacks

Every table that holds your data runs Postgres row-level security in its strictest mode, and the role Ray runs as physically cannot bypass it. We prove it by having one workspace try to read another's, eight different ways. All eight are blocked, and our build fails if a new table ever ships without the lock.

Failed work never costs you.

If Ray loops, stalls, or errors, that work is never counted and never billed. You pay only for tasks that actually land.

Your messages never hit a log.

Ray reads a channel to do the job, then lets it go. Raw messages are never written to any log, and our analytics see counts and costs, never content.

It works only where you invite it.

Ray acts in the channels you add it to and nowhere else. It never carries a secret into view, and it never wanders the rest of your workspace.

We don't do anything clever with your data.

Ray uses your data to do your work, and that is the only thing it is ever used for.

  • We never train AI on your data.

    Not us, and not the providers we send prompts to. Their API terms keep your data out of training.

  • We never hand your data to ad platforms.

    No marketing identifiers handed to ad networks, ever. Ray is a subscription, not an ad business.

  • We never log your raw messages.

    Ray reads what it needs in the moment and writes none of it to a log.

  • We never touch a channel you didn't invite.

    Add Ray where you want it. It stays there, and it never reaches past it.

You hold the controls.

Ray's memory is yours to see, correct, and erase, all in chat, with no dashboard to dig through.

Priya

Ray, what do you remember about the mobile launch?

RayApp

Three things I'm holding onto:
  • Priya owns the mobile roadmap
  • Design reviews are on Thursdays
  • The team ships on Fridays

Priya

Forget the Thursday one.

RayApp

Done. That memory's gone.

An admin can wipe it all at once, or switch memory off entirely. And when you leave, Ray deletes what it kept and revokes every token. Short-lived logs age out within 30 days. Read it in the privacy policy.

The questions security teams ask first.

The short version is on this page. The long version is the policy, and if we haven't answered something, just ask.

Read the full security policy

Autonomous, and accountable.

Bring Ray into your team. Watch it work, approve what matters, and check any of this whenever you want.