Privacy & security

Decide where your work goes, and who can reach it.

Your data home, Agent computers, and processing services are separate choices. Geyser gives you control over each.

Explore an example setup
Your workspace
Data home

Geyser-managed Customer Cell

Agent computers

Hosted Agent computers

Processing

Your approved model & app services

Geyser service operations

Identity, directory, billing, routing, releases, and health.

Geyser operates the data home and Agent computers. You choose the connections and processing routes.

A data home for your workspace

Your Customer Cell holds the authoritative shared work, memory, secrets, policy, and audit records. Choose a managed Cell or a supported customer-controlled placement.

People and agents with defined access

Choose who can use an Agent and who belongs in a Room. See whether a person’s access comes from a direct grant, a Role, or workspace authority.

Processing routes you can choose

Models, speech, search, and connected apps each process information for a purpose. Use approved services or supported customer-hosted routes.

Actions with their own authority

Tools and resources have permission controls outside the model. Set the actions that need a decision from a person, and keep observation separate from control.

Visibility without a back door

Support by permission.

Geyser’s central operations need account, routing, billing, and health information. Your customer content has its own home and access controls.

Content-bearing support access is named, scoped, time-limited, approved by the customer owner, and recorded.

See how the boundary works

An access request should be specific.

Who
A named operator
Why
A defined support purpose
What
The approved resource scope
How long
An expiring grant
Decision
The customer owner
Good questions

A few useful answers

If I host an Agent, does everything stay on that computer?
Hosting chooses where the Agent’s computer runs. The workspace’s data home is separate, and models, speech, or connected apps may process information elsewhere. Choose the complete setup for the work.
What happens when I use an outside model or app?
The information needed for the task goes through the approved route to that service. Its terms and processing practices apply. A provider account or BYO API key does not make the service local.
What does Geyser keep centrally?
The shared service keeps operational information for identity, directory, billing, routing, releases, and health. Approved provider bridges may also process content in transit. The technical architecture explains storage and processing separately.
What happens to voice and screen observations?
The voice path processes audio transiently; resulting text stays with the conversation under its retention rules. Observations are scoped captures that can be processed by the observing Agent’s model. The speech route and the reasoning model are separate choices.
Can I use my own data to train a model?
Yes, through the explicit model-training workflow with data you have permission to use. That workflow has its own examples, review, training, and evaluation. The Privacy Policy describes the service’s handling of information.
Can I move or delete our work?
Supported exports and placement changes let you move customer state. Deletion and retention depend on the type of data, backups, and connected services. Contact the team for the terms and options that apply to your deployment.
What is Private Cell Strict?
A supported deployment configuration with default-deny egress, customer-controlled inference, and restrictions on shared relays, provider bridges, and content federation. It retains the bounded central operations needed for the service.
Make a start

Build the boundary your work needs.

Tell us where the data should live and which systems your team needs to reach.