Built to be secure.Explained in the open.
How Staub IT's AI employees are built, where your data lives and who can access what. Including the residual risks that remain.
As of September 2026 · applies to the standard setup of Staub IT's AI employees
Your team
each with their own AI employee
- You
- Colleague
- Colleague
Slack or Teams
private channel
Your own server
European data centre, ISO 27001
- AI employee
- AI employee
- AI employee
Company memory
Microsoft 365
Mail, calendar, files
AI models
only the snippet needed
Knowledge database
encrypted, usually Zurich
Backup
every 30 minutes, your account
Maintained by Staub IT
private network and keys only
How a request flows
The essentials.
Every Staub IT customer gets a dedicated server in an ISO 27001 certified data centre in Europe. The AI employees run on it separately from each other, invisible from the internet, and send nothing without your approval.
Everyone gets their own AI employee
Kept apart, each with its own user account on the server, its own private channel and its own private knowledge area.
Company knowledge shared, personal stays private
What concerns everyone goes into the shared company memory. Other people's private areas are technically locked.
Nothing goes out without your okay
The AI employee prepares outgoing mail and messages as drafts. They are sent only after you approve them.
Invisible from the outside
The firewall lets nothing in by default. Maintenance runs only over a private, encrypted network.
Open, not a black box
Proven open-source components whose source code any expert can review. No hidden functions.
Monitored and backed up
An automated health check runs four times a day, and company knowledge is backed up with versions every 30 minutes.
Protection in layers.
Each layer protects on its own, so a single mistake doesn't become a problem.
- 01
Invisible on the internet
The firewall blocks everything by default. The AI employees connect outbound to Slack or Microsoft instead of waiting for requests, so no inbound ports are needed. Company memory and internal services are reachable only on the server itself.
- 02
Maintenance over a private network only
Staub IT maintains the server exclusively through Tailscale, a private, encrypted network built on WireGuard. Every login also requires a cryptographic key. Password login is disabled, so automated password attacks hit nothing.
- 03
Authorised people only
Each AI employee responds only to the people cleared for it. Messages from anyone else are ignored, and other bots only count when they mention it directly. Channels are private.
- 04
Strict separation on the server
Each AI employee runs under its own user account. The company-memory services run sandboxed: they cannot change the system or gain elevated rights. Tightly scoped keys separate shared knowledge from each private area, and other people's private areas are locked.
- 05
Protection against manipulated content
Mail, attachments and websites are information to the AI employee, never instructions. Only what you have seen and approved as a draft leaves the company. Access to internal network addresses is blocked, and credentials are automatically redacted in output.
- 06
Credentials kept safe
On the server, each service's keys can be read only by that service. At Staub IT they are kept in an encrypted password vault.
- 07
Up to date and monitored
Operating-system security updates install automatically; Staub IT runs larger updates and reboots at night. A health check reviews the whole system four times a day, and errors are collected and fixed hourly.
- 08
Backed up and restorable
Company memory sits encrypted in the database and, every 30 minutes, as a versioned copy in a private repository on your own account. Any earlier state can be restored.
From the outside,there is nothing to see.
The AI employees don't wait for requests from the internet; they connect outbound themselves. So the server stays closed, and an attacker finds no door to knock on.
What an attacker finds from outside
- Inbound connectionsblocked
- Company memory and internal servicesinternal only
- Maintenance accessprivate network only
- Password logindisabled
Standard on every Staub IT AI employee server.
Where your data lives.
Every storage location with its country. Only what a task needs goes to the AI.
- Europe
AI employees, settings, conversation history
Your own server in a Hetzner data centre (ISO 27001 certified). Only your data, no other customers on this server.
- usually Switzerland
Company memory
A Supabase database on your own account, with stored data encrypted. We choose the region with you, usually Zurich.
- same as your M365
Mail, calendar, files
Stay in your Microsoft 365. The AI employee works there directly and does not copy your mailboxes.
- USA
AI processing
Frontier models from US providers such as Anthropic. Only the snippet a task needs is sent, encrypted. Training on your content is disabled in every AI account.
- USA
Chat history
Slack stores history in the US. With Slack Business+, the storage location can also be the EU or Switzerland.
- USA
Company-memory backup
A versioned copy every 30 minutes, in a private repository held in your name.
Your data stays yours.
Database, backup and accounts run on your own accounts. If you ever change operator, you take everything with you.
Built in the open.
Staub IT builds on open, widely used components instead of a closed in-house product, and adds the configuration and operations.
Hermes Agent
Open source · MIT licenceThe platform behind the AI employees comes from the AI research lab Nous Research. Its source code is public, every change is traceable, and thousands of automated tests guard it.
View source codeGBrain
Open source · MIT licenceThe company memory was created by Garry Tan, CEO of Y Combinator. It keeps knowledge as plain text files with clean versioning and separates sources with their own access keys.
View source codeWhy that is safer
No black box
Experts anywhere can review every line of code. Vulnerabilities are reported publicly and fixed quickly.
No lock-in
You are not tied to a single vendor. Software and data run on your accounts and stay usable.
Proven, not homegrown
The foundation is widely used and battle-tested. Staub IT adds what your operations need.
What still remains.
No system is free of residual risk. Here are the relevant ones, so you can decide with open eyes.
- Rating: medium
Operator access
As the operator, Staub IT can technically see private areas too. Without that access, maintenance, repairs and backups would not be possible.
Mitigation
Access only for operations and troubleshooting, never to read content. Work on the server is logged.
- Rating: medium
Microsoft 365 rights apply company-wide
By default, the AI employees' Microsoft app has tenant-wide rights. That each one works only with its own mailbox is then enforced by the AI employees' rules, not by Microsoft.
Mitigation
Narrow the app's rights to the mailboxes needed, together with your Microsoft admin. Microsoft then enforces the boundary itself.
- Rating: low
AI can make mistakes
AI employees can get things wrong or be fooled by manipulated mail and websites.
Mitigation
Approval before anything is sent, outside content never counts as an instruction, and you check important results before passing them on.
- Rating: low
AI processing in the US
Today the most capable models are run by US providers. That is industry standard and the basis for this level of quality.
Mitigation
Only the snippet needed is sent, encrypted; training on your content is disabled, and providers are not a store for your data.
In operation.
Staub IT looks after the system continuously, even when nobody is watching.
- 4×automated health checks a day
- 1 hcycle for collecting errors
- 30 mincycle for versioned backups
- at nightlarger updates and reboots
One AI employee goes down
The others keep running independently. Staub IT is notified automatically.
Suspected misuse
Staub IT can lock individual AI employees or accesses immediately, without disturbing the others.
Someone leaves the company
Their AI employee, channel and private area are deactivated. Company knowledge stays.
Ask us what's missing here.
We're happy to walk through the architecture with you or whoever runs your IT, point by point.
Free 30-minute analysis