Architecture
What enters, stays.
Senior professionals carry decisions they cannot say out loud in any room they live in. Say them to a board and the relationship shifts. Say them to a spouse and the weight transfers. Say them to a coach and they become a file. Persona iO is built for those decisions. It is not therapy, coaching, or executive advisory.
The system has two parts, and they carry different guarantees. We keep them separate on this page because the difference is the whole point, and we would rather show you the seam than paper over it.
What the system stores, it cannot read. That is enforced by mathematics. How the conversation behaves in the moment is enforced by code we commit to maintaining. We mark which is which, every time, because a guarantee you cannot tell apart from a promise is worth less than one you can.
The vault.
What the confidante remembersWhen memory is on, what the confidante retains across sessions is encrypted on your device before it is ever stored. The guarantees here rest on mathematics, not on our conduct. You can audit what is held and redact any of it, and a redaction destroys the stored record rather than hiding it. You can also turn memory off entirely, in which case nothing is stored at all.
Your stored memory is unreadable to us.
Enforced by mathematicsWhat a confidante remembers about you is encrypted on your device with a key derived from your passphrase. The key is never transmitted. We hold a file we have no way to open. A subpoena reaches ciphertext. An acquirer buys ciphertext. A breach exposes ciphertext. This holds even if we want to break it, are ordered to, or no longer exist.
The limit. Encryption protects the stored file. It does not protect a compromised device or a camera over your shoulder.
Institutional failure reaches nothing readable.
Enforced by mathematicsWhat we never possessed in readable form cannot be extracted from us. The encrypted vault is unintelligible to everyone except the person who holds the key. This is the same mathematical wall, stated as a consequence: there is nothing readable for failure to reach.
The limit. It cannot protect against a third party you bring into the room, or your own choice to repeat what was said.
We cannot accumulate stored leverage against you.
Enforced by mathematicsBecause we cannot read the vault, we cannot build a profile from it, cannot sell it, and cannot hand a usable record to a future owner. The structural inability to read is also a structural inability to hoard. This follows from the encryption and carries the same weight.
The limit. It governs what we store, not what you choose to expose elsewhere.
The session.
The live conversationA confidante has to read your words to answer them. So during a live session, what you write is processed in the clear, in the moment, to generate the reply. There is no way around this for any system that responds in language, and we will not claim otherwise. What protects you here is not that the words are unreadable in that instant. It is what happens after.
The connection is encrypted in transit. If you keep memory off, the conversation is held only long enough to answer and is never written to storage we can read. If you turn memory on, what persists is encrypted into the vault above, under your key. The guarantees in this section are enforced by code we commit to maintaining. They are real, and they are a different kind of promise than the mathematics of the vault. We mark them so you always know which you are standing on.
You hold the only key, and we cannot recover it.
Enforced by mathematicsYour passphrase becomes your key on your device and never leaves it. We store the random salt, which is not a secret, and never the passphrase or the key. If you forget the passphrase, your stored memory becomes permanently unreadable, to you and to us alike. That is the cost of a key only you hold, and we will not pretend otherwise.
The limit. Write the passphrase somewhere safe. We cannot reset what we were never given.
The confidante does not announce that it remembers.
Enforced by codeWhen memory is on, the confidante carries continuity the way someone who has known you for years does, woven into the reply rather than flagged as evidence. A filter removes phrasing that surfaces memory as a discrete artifact before it reaches your screen. You return to old ground without managing a relationship that quotes your past back at you.
The limit. This is enforced by code we commit to maintaining, which is a weaker guarantee than the encryption above, and we state it as such. It does not stop a determined reader from inferring continuity on their own.
The session does not orient around your position.
Enforced by codeThe system withholds institutional data from the confidante and instructs its responses against scale-adjacent language. The session orients around the person carrying the weight, not the title generating it.
The limit. This is enforced by code, not mathematics. It does not stop you from making your own scale the subject.
The session does not perform loyalty.
Enforced by codeThe confidante does not flatter, does not reassure for its own sake, and does not ask for anything back. A filter blocks loyalty-performance phrasing and the system prompt instructs against generating it. You carry no reciprocal obligation.
The limit. This is enforced by code, not mathematics. It cannot stop you from perceiving loyalty in consistent behavior, or from forming an attachment to it.
Persona iO admits members two ways. A current member may introduce you. Or you recognize yourself in what is written here and apply directly. Both paths end in the same standing. There is no third path, and the architecture does not market itself further.
Request Access
