your CISO assistant · asks in words · proposes rules · you approve
Talk to Rocky. He proposes, you approve.
Rocky reads how your organization is already shaped and drafts the rules in plain language. He can’t switch a single one on. Nothing is enforced until a human approves, and neither Rocky nor NoData ever sees the data itself.
🔗 Rocky sits on the hierarchy you already have, read from your M365 / Google directory. Migrates nothing · replaces nothing · proposes only, you approve.
R
Rocky
CISO assistant · proposes · content-free · signed receipts
🧠✋ proposes, never enforces🙈 content-free: NoData never sees your data🔑 least-privilege: can’t self-grant⛓ bound by iron-rules (AI-never)🧾 every move = signed receipt
Your organization
Rocky hasn’t looked yet, press Start.
⛓
Human approval gate
Rocky's proposals are inert until you approve. Only approved intent crosses this line.
proposed 0enforced 0
Your data · policy travels with it
national_id
Clients
open · default
client_name
Clients
open · default
policy_premium
Clients
open · default
claim_amount
Claims
open · default
medical_note
Claims
open · default
bank_account
Finance
open · default
agent_commission
Finance
open · default
price_offer_link
Sales
open · default
regulator_report
Compliance
open · default
The sign language of control
Every mark is one rule, enforced per request. Dashed = proposed by Rocky · solid = approved by you.
🎯Scoped · only the right role / own records
🎭Masked · value hidden, never shown in full
📊Aggregate only · totals yes, raw rows no
⛔AI-never · the assistant may never read it raw
👁View-once · opens a single time, then gone
👤One recipient · bound to a single person
🚫No forward · view in-app · never an email attachment
⏳Expires · access self-destructs after a window
📅Time-locked · sealed until a release date · then opens
💧Watermarked · forensic trace per viewer
🔥Burns on revoke · downloaded copies die too
🧾Signed receipt · every access proven, content-free
your turn · personal, not generic
Now do it on your organization.
how it is built
One engine. Three layers. One source of truth.
The boundary between human judgment and machine automation is the architecture, and it is what makes the model safe in the AI era.
Control Surface🟢 you · interface only
You describe the business: departments, information types, sensitivity levels, who approves what, and how AI may use data. These are business decisions, they stay with you.
↓ answers, edits, explicit approvals
Intelligence Layer🟣 AI · non-authoritative
AI suggests structure, auto-classifies, and explains risk in plain language. Every output is a proposal: it reaches the core only through human approval. It never writes policy by itself.
↓ only human-approved intent crosses this line
Deterministic Core🔵 the processor · no AI, ever
The Compiler turns approved intent into a policy graph, the Runtime enforces it in real time (deny-by-default), and every decision becomes a signed receipt. Same input ⇒ identical output. No guessing.
why a new category
Identity systems scale complexity. Data systems scale policy.
Classic IAM grows roles, groups, and exceptions faster than the organization itself. A policy graph grows with your data, not with your users.
Identity-based security
scales with users
requires roles, groups, exceptions
1 org change → 10–100 permission edits
breaks under AI-driven access
Data-based security
scales with information
compiles policy deterministically
1 policy change → re-compile the graph
works natively with AI agents
IAM systems manage people. We compile how data is accessed.
ניהול משתמשים מייצר מורכבות · ניהול מידע מייצר סקייל
the engine that makes it all possible
It all runs inside the Capsule.
The Capsule is the processor, installed on your side, running locally. It is the one thing you install; everything else is a policy you compile onto it. Your data and your keys never leave. We compute access to information, without access to the information itself.
💠 Installed Capsule · runs locally🔒 Local · offline · zero-knowledge🔑 Your keys, never ours📜 Signed receipt for every access🧩 Install once · compile policies forever
Describe your organization. The processor does the rest.
Policy Compilation Engine for the AI era · we compute access, not permissions