Trust & security
Architected guardrails and real security. Not a privacy policy and a prayer. Every boundary Fred holds is enforced in code before a word reaches your visitor.
An airline’s chatbot invented a refund policy, and a court held the airline to it. The bot’s words were the company’s words. That ruling is why Fred is built the way it is: when an AI speaks for your business, “the model usually behaves” is not a safety plan.
Every install runs an industry pack and regional rules, and you can add unlimited custom rules on top. The packs are the floor, not the ceiling.
This is what “never out of line” means in practice. Not four values on a poster, four systems that run on every conversation.
Scope discipline blocks code-for-hire, jailbreak attempts, and off-topic abuse. Industry and regional packs add the rules of your trade and your country, more than 50 of them ready today. And crisis language always routes to crisis resources. That one cannot be turned off.
Conversations flow through your own AI provider keys. Your rate limits, your usage dashboard, your data relationship. Your conversations are not used to train provider models, and we do not tax every message on the way through.
Sensitive data is scrubbed before it ever reaches an AI provider. Rate limiting resists automated abuse and runaway spend. Regional packs load the right privacy rules for the US, EU, UK, Canada, Australia, and New Zealand. See the regional rules →
Every guardrail action is logged. When a rule fires, you can see the rule, the trigger, and the response, ready for a compliance review instead of a shrug. Webhook payloads to your CRM are signed, so your systems can verify every delivery.
Want the layer-by-layer tour, baseline to custom rules? See how the guardrails work
Talk to Fred.
You do not assemble any of this. The right protections switch on for your business and your country the day Fred goes live.
In a regulated industry? Fred is built for healthcare, finance, and legal compliance workflows, with a pre-built pack for your field. Find your industry
256-bit encryption for data at rest and TLS for data in transit. API keys are encrypted before storage and decrypted only in memory while a request runs. They are never logged and never visible in admin panels.
Sensitive data like emails, phone numbers, card numbers, and Social Security numbers is scrubbed before it reaches an AI provider and before transcripts are stored. A strict mode goes further, softening names and generalizing locations for industries with heightened requirements. You choose the mode, Fred enforces it automatically.
Transcripts are stored with consent, and visitors can request access or deletion. The privacy tooling is built for GDPR, CCPA, LGPD, and PIPEDA workflows, consent prompts, data export, one-click removal, and a Data Processing Agreement on request. We say alignment, not certification, and we will put that in writing.
Jailbreak patterns are blocked deterministically by rules that run in code, outside the model, so a clever phrasing cannot talk its way past them. In Fred Cloud those rules run on our servers; in the WordPress plugin they run inside the plugin on your own hosting. This is AI governance enforced, not suggested. Outbound requests are hardened against SSRF, so Fred cannot be tricked into calling systems it should not.
Payloads are signed with HMAC so your systems can verify every delivery came from Fred and was not altered in transit. Lead data lands in your CRM, not in a third-party inbox.
Through a protected build pipeline with signed, tamper-resistant distribution. What arrives on your site is what we shipped, verified cryptographically, with updates delivered the same way.
The same guardrail and privacy model, plus request tracing with OpenTelemetry for operations teams. Fred Cloud is coming soon. Join early access
Request the compliance documents, or bring your reviewer’s questions straight to us. Fred is in the corner of this page if you want to test the boundaries yourself.