Wrong with receipts beats right with no audit trail.
Built for founders who’ve been burned by AI tools that lose code, leak credentials, and forget last week’s decision. Here is what we never do, what we record, and what happens when something goes wrong.
We never ask for credentials in chat
No API keys. No database passwords. No secrets in the conversation. Paste them into your env file, not your AI.
We never make your project public by default
Every project is private from message one. There's no public toggle, no shareable preview link, no surprise indexing.
We never train on your data
Inference goes through API providers under their no-training terms. Your project memory lives only in our database. Your conversations don't become anyone's training set.
We never lose your work
Persistent project memory, decisions log, and weekly briefing runs keep state across sessions. Close the tab — come back next month — your project is still there.
The shortest list on this page. Every line is a guarantee, not a roadmap item.
Neveryour keys in chat
Credentials stay out of the conversation.
No API keys, no database passwords, no secrets in chat. Paste them into your env file, not your AI.
Please don’t paste keys in chat. Connect Stripe from Integrations instead: it’s read-only, and you can revoke it any time.
Stripe · read-only connector
Credentials stay out of the conversation.
1 / 3
It’s late and you want MRR in the brief. You paste a live Stripe key into the chat.2 / 3
The team won’t take it. Ops points you at a read-only connector you can revoke.3 / 3
The number arrives the safe way. The key never becomes part of the conversation.
Alwayson the record
Reverse anything. Nothing is rewritten.
State changes are first-class. The call, the dissent, the reversal, and the reason for it all stay on the log.
Pricing
Day 9 · Fin, Nia, Coordinator
Accepted: $19/mo, no free tier
Day 40 · Nia
Dissent revisited: trials at 22/month
Day 41 · You
Reversed: capped free tier added
Rollback trigger fired: fewer than 30 trial starts.
Nothing is rewritten. The Day 9 call is still on the record, next to why it changed.
1 / 4
Day 9: pricing is accepted with Nia’s dissent attached.2 / 4
Day 40: the numbers side with Nia. The dissent is still there to revisit.3 / 4
Day 41: you reverse it. The reason is logged next to the original call.4 / 4
Week 3 you can scroll back to exactly what the team thought, and why it changed.
Yoursto control
Support access is visible, logged, and switchable.
Paid plans turn on read-only support access so we can help when something breaks. On the $1 trial it stays off until you opt in.
Allow support access
On by default for paid plans. Off on the $1 trial.
- 14:02 support session started
- 14:03 viewed /channels/finance
- 14:07 viewed /settings/billing
- 14:09 session ended · kept 90 days
Toggled off. Your call, any time.
1 / 4
Support access is a toggle in Settings → Privacy, not a hidden back door.2 / 4
When support is viewing as you, a banner says so, on every page.3 / 4
Every operator session is logged with timestamps, and every page visited is kept for 90 days.4 / 4
Toggle it off whenever you like. It’s your workspace.
Underneathdefense in depth
The boring infrastructure that holds it up.
Every line names a real vendor or a real practice.
- Auth
- Clerk-managed sessions. We never see or store your password.
- Database
- Postgres on Neon. Encryption at rest. Row-level isolation per organization.
- Secrets
- Secrets live in the deployment platform's encrypted environment and AWS Secrets Manager. Nothing sensitive is committed to git.
- AI
- Frontier models through API providers under no-training terms. The model is named on every message; we don't hardcode it here.
- Code review
- Every change is reviewed by Claude Code and a human. CI runs Biome and tests on every PR.
- Vulnerability disclosure
- security@origin8.app. We respond within 48 hours. No legal threats for good-faith research.
Found something we missed? Email security@origin8.app. We respond within 48 hours.
By design
You ship. We advise.
Origin8 is not a code generator. We don’t ship to production for you. We don’t auto-deploy. We don’t run your app. We don’t hold your AWS keys.
The failure modes of full-autopilot agents (forgotten context, hallucinated APIs, exposed secrets, deleted production databases) become your problem the moment we take the wheel. So we don’t take it.
If you want a tool that types code and pushes it live, you have great options. We help you decide what to build, capture the reasoning, and remember it next week.
When something goes wrong
Things will go wrong eventually. Every honest software company says this. Here’s the playbook before it happens, not after.
- 1
We notify affected users within 24 hours of confirmed impact
In plain language, naming what happened and what data was touched.
- 2
We post-mortem publicly within 7 days
Root cause, timeline, what we changed, what we're still learning. Published at /trust/incidents when there is anything to publish.
- 3
We never blame our customers, our docs, or the bug reporter
If a user could trigger it, that's on the design. If a doc was unclear, that's on us. We owe the report a thank-you, not a legal threat.
Straight answers
Does Origin8 train on my data?
No. Inference runs through API providers under their no-training terms, and your project memory is stored only in our database. Your conversations don't become anyone's training set. The model that answered is named on every message.
Will Origin8 ask for my API keys or database passwords in chat?
Never. No API keys, no database passwords, no secrets in the conversation. We expect you to keep credentials in your env file, not your AI.
Are my projects public by default?
No. Every project is private from message one. There is no public toggle, no shareable preview link, and no surprise indexing.
How does Origin8 prove what an AI message is based on?
Every AI message has a 'Why?' chip. Tap it to see the model that wrote it, the sources and files it read, the tools it called, and the caveats it attached. When no sources were recorded, it says so.
Can I export my data and leave?
Yes. Markdown export of every channel, every decision log, and every weekly brief. Your data is exportable in formats you can open without us.
Who can access my project from Origin8's side?
Paid plans turn on read-only support access automatically so we can help when something breaks. On the $1 trial it stays off until you explicitly opt in. You can toggle it off in Settings → Privacy anytime. Every operator session is logged with timestamps; you'll see a banner whenever support is viewing as you, and every page they visit is recorded for 90 days.
What AI model does Origin8 run?
Whichever model the 'Why?' chip on the message says. We don't fix a model name in marketing copy because it has changed once already and will change again; the chip is the source of truth. Providers are used under no-training API terms.