nerrem.ai

Built to protect
what’s yours.

Not policies. Mechanisms. Your data, your budget and your projects — here’s what we built for each.

Your data

Your own machine
An isolated machine we run for you alone — free accounts too. Never a shared box.
Encrypted, and you can hold the key
At rest and in transit. No plaintext mode — not for support, not for convenience.
Never trained on. Never sold.
There’s no ad business here. Nobody to sell you to.
Yours to take
Export everything, any time. Stop paying and nothing is deleted.

What we can see: your content, briefly, inside your own machine, to do the things you ask for. Hold your own key and even that goes away. Self-host and it never reaches us at all.


Your budget

Everything is prepaid
Your plan buys the month up front. No meter running against your card.
Agents work inside budgets you set
And they can’t raise their own. Nothing runs away with your credits overnight.
Nothing tops itself up
More is a thing you buy, at a price you see first.

Your project work

Agents write to a copy
Each one gets its own branch of your project. Your actual files aren’t touched until you accept the work.
One door for every tool
Every action passes one checkpoint that decides what it’s allowed to do. No side entrances.
Boxed in by the operating system
Code runs seeing only the files that job needs — enforced by the kernel, not by asking nicely.
Nothing goes out without your say-so
Sending mail, posting, paying — those fail closed unless you allowed them.

On prompt injection. Anyone claiming their AI can’t be tricked is overselling — a model reads text and can’t always tell instructions from content.

So we don’t rely on it behaving. We shrink what it can touch. A tricked agent still can’t mail your files to a stranger.


No SOC 2 yet. We’re a small team in private beta — we’d rather say that than imply otherwise. Anything else you need to know before you trust us with your work, just ask: security@nerrem.ai