Not another chatbot.
It's your agent.
A single layer of intelligence and action across your whole digital life. You speak to it, it knows you, it connects to your services and works for you — within the permissions you define and leaving a record of everything it does.
- Voicethe main interface
- Any modelnot tied to just one
- Bankread-only
What do I have tomorrow? And check how much is left on my card.
Tomorrow you have 3 meetings; the 10:00 one with Juan clashes with your focus block. Your card has 62% of its limit available. Shall I move the meeting with Juan to 15:00?
- Model Routersimple task → cheap model
- Permission Enginecalendar.read ✓ · bank.read ✓
- API ConnectorGoogle Calendar over OAuth
- Credential Vaultbank session without exposing the password
- Browser Agentbalance → structured result
- Confirmationcalendar.move needs your “yes”
Today you are the integrator between ten applications.
Each service has its own interface, credentials, permissions and context. The agent sits on top of all of them and lets you ask for things the way you would say them out loud.
- Gmail
- Calendar
- Tasks
- Drive
- Bank
- Card
- Stores
- Search
- Sites with no API
- “What important email came in last night?”
- “Move the meeting with Juan.”
- “Find the price of the shampoo and remind me to buy it tomorrow.”
- “Check my messages and tell me if anything is urgent.”
One brain, many hands and a guard that does not negotiate.
The model interprets what you want. Everything else — permissions, secrets, execution and record — lives outside it.
- Voice Layercaptures, transcribes and answers by voice
- Agent Coreintent, context and coordination
- Model Routerwhich model to use for each task
- Memorywhat it knows about you
- Permission Enginewhat is allowed and what is not
- API Connectorwhen the service has an official API
- Browser Agentisolated, when it does not
- Schedulerworks without you asking
- Audit Loga record of every action
The model ≠ your keys
It can say “I need to check the balance”. It can never ask for the password.
It receives a result, not a secret. That sentence is the entire security architecture in short, and it is what makes delegating defensible.
- 01You ask how much you have in the bank
- 02The Permission Engine validates connector, action and policy
- 03The tool requests the session from the Credential Vault
- 04An isolated browser enters the bank site
- 05It returns a structured result, not a screen
- 06The model receives the figure. The key never entered its context
You decide what it does alone, what it asks you about, and what it cannot touch.
Set once, for each connected service. After that you just talk.
| Does it alone | Asks you first | Cannot, full stop | |
|---|---|---|---|
| Gmail | read · search · summarize | send · reply | — |
| Calendar | read | create · move · cancel | — |
| Bank | balance · transactions · credit used · billing | — | transfer · pay · invest · change payees |
In the first version the bank is read-only. It moves no money, and that cell is empty on purpose.
You decide how much it does on its own.
Four levels, from less to more delegation. Every autonomous action goes through the same policies and is recorded.
- 1When you askacts only if you speak to it
- 2Scheduledruns tasks at a set time
- 3Proactivedetects and alerts you
- 4Autonomousexecutes what is authorized without asking each time
PepeR asks. AgentiR is who answers.
They are the two ends of the same conversation, which is why they live in the same house. When a person's agent looks for someone who can solve something, on the other side there has to be a company that understands the question, answers with real data and leaves a record.
Their agent. It asks, compares and resolves for them, with their permissions.
The infrastructure that makes it legible and operable when that agent arrives.
In PepeR, the model never sees the password. In AgentiR, payment data never enters the room. It is the same principle on both sides — whoever reasons does not touch the credentials — and it is no coincidence.
What this does not mean
- AgentiR has no consumer app. We do not talk to the person who buys, nor compete with the assistant they already use. Our client is the company.
- PepeR is not a requirement for anything. A company on AgentiR serves any properly identified agent, wherever it comes from. The front desk names by order of arrival and first place is not for sale.
- They are not sold together. They are two products, with two customers and two pricing models.
Where it stands
PepeR is in design: the blueprint and the product definition exist, the service does not. It is not launched, which is why there is no price here. The model will be membership plus capacity — no artificial message caps, and a spending limit you set — and when it can be used it will have its own page.