Security and data

A.S.T.R.A. runs in your own accounts under least-privilege scopes, gates consequential writes behind a human, keeps personal data out of audit logs, and lets you bring your own model.

01

Whose accounts does it run in?

Yours. The systems are built in your CRM, your automation tools and your repos. There is no separate Mindlyft system of record holding a copy of your pipeline, which means there is no second place for it to leak from and no migration if you leave.

02

What can an agent reach?

Only what you scoped. Agent identity is explicit: an agent is granted specific objects and fields on specific accounts, and it has no standing authority to widen that for itself. Least privilege is the starting position, not a hardening exercise after the fact.

03

What stops a bad write?

Three things in order. The scope, which means most bad writes are not reachable at all. The approval gate, which means consequential ones need a person. And the receipt, which means anything that did run can be found and reversed.

04

What goes into the logs?

Interaction patterns, not payloads. The audit trail records the action, the systems, the approver, the timestamps and the rollback path. User-typed content, passwords and personal data are deliberately kept out of it.

05

Which model processes our data?

The one you choose. A.S.T.R.A. is model-agnostic and works with the OpenAI and Anthropic APIs among others, so the provider question is answerable by your own policy rather than by a vendor's default. The intelligence is swappable; the engineering around it is the durable part.

06

What happens if we stop the subscription?

The work keeps running. Because everything was built inside your accounts, cancelling ends the engineering relationship, not the automation. There is no minimum term, billing runs in 4-week cycles, and unused days bank and roll forward.

07

Who actually does the work?

Mindlyft, working with you directly. There is no account manager relaying requests to somebody you never meet.

FAQ

Questions

Where does A.S.T.R.A. store our data?

In your own systems. Everything we build lives inside your CRM, automation tools and repos, so there is no separate Mindlyft copy of your pipeline.

What permissions does an A.S.T.R.A. agent have?

Only the objects and fields you scope to it on the accounts you allow. Least privilege is the default and an agent cannot widen its own scope.

Can we bring our own model?

Yes. A.S.T.R.A. is model-agnostic and works with the OpenAI and Anthropic APIs among others, so the provider decision follows your policy.

What is kept out of the audit logs?

User-typed content, passwords and personal data. The logs record the action, the approval and the target, not the sensitive payload.

Free GTM Engineering Review

Thirty minutes on your GTM engine.Free. No pitch deck.

A working session, not a sales call. We map where your company's knowledge lives, where promises leak, and the first systems we would build, and we tell you straight if it is not worth doing yet.

Or pick a time