---
title: "Security: what Alive can do, and what it cannot"
description: "Per tool, what Alive does by itself, what waits for your click and what it cannot do at all. Where your data goes, what you can read back, and what we do not have."
url: https://ali.ve/security
language: en
---

# What Alive can do, and what it cannot

Safe is not something you can check. A list is. This is ours: per tool what Alive does by itself, what waits for your click, and what it cannot do at all.

Checked against the product's own feature list on 8 October 2026.

## Three things it cannot do

### Send mail

There is no send button in Alive. It saves a draft in your own mailbox, in Gmail, Outlook or any IMAP mailbox, and you send it from there yourself.

### Change your calendar on its own

Creating, moving or deleting an event waits on a card in the chat until you press it.

### Delete files in Google Drive

It creates files, edits their text and moves them. Throwing one away is not something it can do.

## Per tool

Every tool Alive connects to today, and how far it goes in each.

| Tool | By itself | Waits for you | Cannot |
| ----------------------- | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------- | ------------------------------------ |
| Gmail, Outlook and IMAP | Search and read mail, label it, archive it, mark it read, save drafts. | Every draft, until you send it from your mailbox. | Send mail. |
| Google Calendar | Read calendars and events, check when people are free, propose a time. | Creating, changing or deleting an event. | – |
| Google Drive and Sheets | Search and read files, create them, edit their text, move them. Add rows and update cells in a sheet. | – | Delete a file. |
| Search Console | Read your search figures and inspect a page. | – | Change anything. It only reads. |
| GitHub | Commit, push, and open and merge pull requests. | – | Touch a repository you did not pick. |
| Linear | Create and update issues, projects, labels and comments. | – | – |
| Stripe | Create customers, prices, invoices and payment links. Refund, change a subscription, answer a dispute. | – | – |
| Supabase | Read your tables and run SQL. | – | – |
| Your project | Create, change and delete files. Publish the site when you ask for it in the chat. | – | – |

Where a row says by itself, you still decide whether it may. Switch off any single tool of a connection, refunds in Stripe for example, and keep the rest. In your project every saved version stays, so you can take the files back to an earlier one.

## What you set

- Which tools are connected. Disconnect one whenever you like.
- Per connection, which single tools are switched on.
- Which GitHub repositories Alive may use.
- Who sees which project, with roles you write yourself.
- What it may spend: a cap per reply, and a budget per day and per month.
- Per agent, how long a run may take, how many steps and how many credits a day.
- When an agent retires: on a date, after a number of runs, at a credit total, or after repeated poor runs.
- Plan mode, in which Alive only reads and comes back with a plan for you to approve.
- Stop, for a reply or a run while it is going.

## What you can read back

- Every run of every agent, as a short summary or as the full log, with what it cost.
- In a chat, each action Alive takes, while it takes it.
- A usage report: credits per day, per project and per model.
- Per connection, when it was last used and whether that went wrong.
- An email when an agent is stopped or cannot start.

## Where your data goes

It is stored in the EU.

What an agent needs for a task goes to Anthropic, whose Claude models do the work. Their commercial terms say it in one line:

> Anthropic may not train models on Customer Content from Services.
>
> [Anthropic's commercial terms](https://www.anthropic.com/legal/commercial-terms)

- We never train on your data and never sell it.
- Stripe sees payment details when you pay, under its own terms.
- Most of what Alive makes lives in your own tools from the start: drafts in your mailbox, files in your Drive, issues in Linear, code in your GitHub. The code of a project also downloads as a zip.
- The agents themselves, their run history and your chats live in Alive and do not come with you when you leave.

## What we do not have

- A SOC 2, ISO 27001 or similar certificate.
- Single sign-on. You sign in with email and a password, see every place you are signed in, and sign the others out.
- A published independent security test.

Careful is a good way to start. Connect one tool, or begin in Plan mode, and ask us anything before you connect the next.

## Who we are, and how to check

Alive AI B.V., Amsterdam, KvK 42143386.

- [Look the number up at the KvK](https://www.kvk.nl/zoeken/?source=all&q=42143386)
- [The company on LinkedIn](https://www.linkedin.com/company/113256096)
- [Every change, written down each week](https://ali.ve/changelog)
- [Book a call with Lars](https://cal.com/larse/15min)
- [founders at alive.site](mailto:founders@alive.site)

Found something here that does not hold? Write to us. It is the most useful email you can send.

[alive](https://ali.ve/)
- [manifesto](https://ali.ve/about)
- [products](https://ali.ve/products)
- [build](https://ali.ve/build)
- [check us](https://ali.ve/check)
- [What we did](https://ali.ve/roadmap)
- [contact](https://ali.ve/contact)

A small team in Amsterdam building agents that take on the work that would otherwise pile up.

[Security](https://ali.ve/security) [Compare](https://ali.ve/vs) [Privacy](https://ali.ve/privacy) [Terms](https://ali.ve/terms) [LinkedIn](https://www.linkedin.com/company/113256096)

Alive AI B.V. · KvK 42143386 · Amsterdam · 2026
