Skip to content
Autumn 2026 edition

New: troopio Cloud is built in. Your employees keep working with your computer switched off. About troopio Cloud

Control

An employee you hand the keys to must know when to stop.

troopio really acts on your tools. That’s why every sensitive action goes past you, everything is logged, and you can shut it all down in one click. This page says what is done today, what is planned, and what isn’t yet.

Four pillars

What is in place from the very first task.

Not a footnote: it’s the heart of the product, and it’s what you’ll see in the Control Centre every day.

  1. 01

    Approval before action

    Sending an email to a third party, paying, publishing, deleting outside its space, deploying, creating a login: before each of these actions, the agent shows you the exact tool and the exact parameters, and waits.

    This holds whatever the autonomy level. It isn’t a setting: it’s a floor, written into the engine, that the agent cannot change itself.

  2. 02

    A log of every action

    Every tool called, every file read, every email sent is timestamped and kept on your machine (or in your troopio Cloud space), in a register you can read, filter and export.

    You know who did what, when, and with which authorisation. Secrets are always masked in it.

  3. 03

    Stop in one click

    Every task can be cancelled in one click, every schedule paused in one click, and stopping the service halts the whole troupe, access to secrets included.

    Without you having to step in: three refusals within a task pause it; three failures of a schedule suspend it and notify you.

  4. 04

    Visible scope

    For each agent, a plain overview, no jargon: its level, the folders it may touch, the secrets it may use and on which hosts, and what it will never do without you.

    Every right can be revoked in one click. Switching to “Autonomous” requires your explicit consent, point by point.

Approval before action

What you see, every time.

An employee who wants to write to a client shows you the recipient, the subject, the attachment, and waits. You approve, or you refuse with a reason. Everything is logged.

Autonomous
Works on its own in the background. Irreversible actions, or actions towards third parties, are always submitted to you.
Default · with your consent
Cautious
Acts freely within its workspace, asks for your go-ahead for everything else.
Asks for anything that leaves its space
Read-only
Reads, searches and summarises. Changes nothing, runs no commands.
Changes nothing
Demo · 6-second loop · clickable
Portrait of Sacha, customer service
Action · waiting for you

Sacha wants to send 1 email to marc@client.ch

Tool
email.send
To
marc@client.ch
Subject
Your quote no. 2026-0418
Attachment
quote-2026-0418.pdf · 124 KB
Level
Autonomous · human class (email to a third party)

“I send nothing until you have clicked. If you refuse, tell me why: I learn from your refusals.”

No “always allow” here: sending, paying, deleting outside its space or deploying goes past you every time, whatever the level.

Where your data flows

Three blocks, two arrows, no hidden middleman.

Your employee is installed on your premises, or in your troopio Cloud space. It reads your tools, writes after your go-ahead, and the troopio engine only receives the context the task needs.

Diagram: where your data flows with troopioThree blocks linked by arrows. On the left, your tools (email, accounting, files). In the centre, your troopio employee, installed on your machine or in your troopio Cloud space, one isolated space per customer: orchestration, log, permissions, secrets vault. On the right, the troopio engine, which reasons over the context strictly needed for the task. Documents stay on your machine or, if you choose, in your isolated troopio Cloud space.YOUR TOOLSEmail · AccountingFiles · CalendarRevocable access, secrets in the vaultYOUR EMPLOYEE · ON YOUR MACHINEOrchestrationLog of every actionPermissions and safety floorEncrypted secrets vaultSchedules, alerts, reportsOR IN YOUR TROOPIO CLOUD SPACEREASONINGtroopio engine(included in your plan)Receives the task context, nothing moreREADSWRITES · ON APPROVALCONTEXTANSWERYour documents stay on your machine or, if you choose, in your isolated troopio Cloud space.

The troopio engine reasons over the task context, nothing more, and keeps no copy of it. The list of sub-processors is in the privacy policy (in French).

Sovereignty and compliance

What is done, what is planned, what isn’t.

We tell the truth, deadlines included. This list will be updated at every step, and the changelog will keep a record of it.

  • Today

    Your data stays on your machine

    By default, troopio installs your employee on your workstation or server. Files, log, memory and vault never leave your infrastructure.

  • Today

    Secrets encrypted at rest and in transit

    AES-256-GCM vault with a local master key; keys never pass through the troopio engine. In troopio Cloud, the vault stays in your isolated space. All outgoing traffic is encrypted (TLS).

  • Today

    No training on your data by troopio

    troopio trains nothing on your data. On your computer, no copy of your content is kept on the server side; in troopio Cloud, it stays in your isolated space. The troopio engine only receives the context the task needs, and doesn’t keep it.

  • Today

    Complete deletion, employee by employee

    An employee is uninstalled together with its memory, workspace and secrets. You can erase everything yourself, without writing to us.

  • Today

    troopio Cloud: one isolated space per customer, in Europe

    If you choose it, your employees work even with your computer off, in a container and on a disk of your own, never shared with another customer, in Europe; the servers’ disks are encrypted. Once you move back to your computer, your space is kept for 30 days, then erased.

  • Planned

    Dedicated Swiss hosting

    For companies that require Switzerland: your employees on dedicated Swiss servers. Planned, with no date until we can keep it.

  • Planned

    FADP kit: DPA, record of processing activities, sub-processors

    The data processing agreement (DPA) for troopio Cloud is available on request by email; the list of sub-processors is in the privacy policy. The record of processing activities is in preparation.

  • Not started

    ISO 27001 certification

    Not started to date. We will write it here the day the process begins, with a deadline.

Status as of 27.09.2026 · every step is dated in the changelog

The safety floor

What an agent will never do, even in Autonomous mode.

The floor lives in the engine’s code, not in a file the agent could rewrite. A test suite replays it at every engine update.

  • Destructive commands, even disguised ones: deletion outside the workspace, sudo, formatting, force pushes, scripts downloaded and then executed.
  • Protected paths: the vault and its master key, your SSH and cloud keys, any .env file.
  • Any form of secret in an input: refused, and flagged as an exfiltration attempt.
  • The “human class”, whatever the level: email, text message or call to a third party, payment, deletion outside the workspace, deployment, DNS, creating a login, first use of a secret on a new host.
Portrait of Nora, troopio virtual executive assistant, leather diary held against her chest

Nora · executive assistant

“I’ll let you know before I send anything.”

Every employee always introduces itself as an AI. It never signs on your behalf, never talks to a client without your permission, and tells you when it isn’t sure.

No mass cold outreach in the catalogue: it is neither legal in Switzerland nor the kind of colleague we want to offer you.

Frequently asked questions

The questions people ask us about security.

Short answers. For anything else, write to us: we reply Monday to Friday.

What happens if the agent makes a mistake?

It asks for your permission before any irreversible action or any action towards a third party, and shows you exactly what it is going to do. The log shows every step. If you refuse, you give a reason: it takes it into account in the following tasks. Three refusals within a task pause it.

Where is my data?

By default, troopio installs an employee on your computer. It works in your folders, with your tools, and shows you everything. Your files, its log and your secrets stay with you; troopio keeps no copy of them on its servers. If you choose troopio Cloud, they are in your isolated space, in Europe, never shared with another customer.

Who sees my keys and passwords?

Nobody, least of all the agent. You enter a key once in a masked form served locally; it is encrypted in the vault and only used by a connector of the engine, on the hosts you have authorised. It never appears in a command or in the log.

Can I stop everything?

Yes. A task can be cancelled in one click, a schedule paused in one click, and stopping the service halts the whole troupe. An employee is uninstalled together with its memory, workspace and secrets.

Want to see control in action, on your own tools?