πŸ”

Authentication & Access Control

All service connections use industry-standard OAuth 2.0 with encrypted token storage and automatic refresh. Your credentials are never stored directly.

πŸ”‘ OAuth 2.0 Authentication

PA connects to Google and Microsoft services using OAuth 2.0 authorization. You grant access through the official provider login β€” we never see your password.

πŸ”’ Encrypted Token Storage

Access tokens and refresh tokens are encrypted at rest using AES-256. Tokens are stored in isolated, per-user encrypted stores.

πŸ”„ Automatic Token Refresh

Tokens are refreshed automatically before expiry. If a refresh fails, PA asks you to re-authorize β€” never silently failing.

βš™οΈ Granular Permissions

We request only the minimum scopes needed. You control which services are connected and can revoke access anytime from your Google/Microsoft account.

βœ…

Confirmation Controls

Configurable approval gates before the PA takes sensitive actions. Preview-before-execute for operations that modify your data.

πŸ“§ Email Confirmation

When enabled, PA shows you the full email draft β€” recipients, subject, body β€” and waits for your "yes" before sending.

πŸ“… Event Confirmation

Before creating, modifying, or deleting calendar events, PA presents the details and waits for approval.

πŸ”§ Per-User Configuration

Confirmation settings are per-user and per-action. Power users can disable confirmations for trusted operations while keeping them for others.

πŸ›‘οΈ

Content Security

Multi-layered protection against prompt injection, malicious content, and unauthorized actions.

🚫 Prompt Injection Protection

All external content (emails, documents, web results) is sanitized before being processed. Hidden instructions embedded in content are flagged and neutralized.

πŸ“¦ Sandboxed Execution

Custom tools run in isolated sandbox environments. No access to the host system, network, or other users' data. Resource limits enforced.

πŸ”Ž Input Sanitization

All user inputs and external data are sanitized. Suspicious patterns are logged and flagged for review.

πŸ“Š Audit Logging

All PA actions β€” emails sent, events created, tools executed β€” are logged for accountability and audit trail purposes.

πŸ›οΈ

Data Privacy & Compliance

GDPR-compliant by design. Your data is processed only for the actions you request.

πŸ‡ͺπŸ‡Ί GDPR Compliance

Comturk processes data in accordance with GDPR. Users can request data export and deletion at any time.

πŸ“‹ Data Minimization

PA only accesses data you explicitly request. No background scanning, no data mining, no selling to third parties.

πŸ—‘οΈ Memory Controls

You can view, edit, and delete any memory your PA has stored. Full control over what your PA remembers.

🏒 On-Premise Option

For maximum data sovereignty, deploy Comturk on your own infrastructure. Data never leaves your servers. Learn more β†’

Frequently Asked Security Questions

Does Comturk store my email passwords?
No. Comturk uses OAuth 2.0 β€” you authenticate directly with Google or Microsoft. We receive a token that grants limited access, and we never see your password.
Can the PA send emails without my approval?
Only if you've disabled email confirmations in your settings. By default, PA shows you the full email draft and waits for explicit approval before sending.
Is my conversation data used to train AI models?
No. Your conversations are not used to train or fine-tune any AI models. Conversations are processed only to generate responses for your current session.
What happens if I disconnect a service?
When you disconnect a service (e.g., Gmail), the stored tokens are immediately deleted. PA will no longer be able to access that service until you re-authorize.
Are custom tools secure?
Yes. Custom tools run in an isolated sandbox environment with no access to the host system, network, or other users' data. Resource limits (CPU, memory, execution time) are enforced.
Can I get Comturk on my own servers?
Yes. Comturk offers an on-premise deployment option with Docker. All data stays on your infrastructure. Learn more about on-premise β†’

Your Privacy Is Our Priority

Start using your AI Personal Assistant with confidence.

Start for free β†’