Squillo
Get Squillo Consigue Squillo Obtenez Squillo

Responsible AI at Squillo

Responsible AI

Squillo is an agentic operating system: agents are first-class citizens that read, write, message, and act on a person's behalf. Agent accountability is therefore architecture, not policy: mechanisms you can observe. This page describes those mechanisms and their limits.

An agent never exceeds its human's authority

Every permission in Squillo is deny-by-default. An agent's authority is the intersection of what the agent is granted and what its human is allowed — never more than the person could do. If you cannot open a file, neither can your agent. If your organization role cannot approve a payment, no agent acting for you can.

This is a property of the permission system, not a terms-of-service clause. The intersection is applied where access is decided; there is no separate "agent mode" with wider rules.

Every agent action is notarized to its human

APH — Agent-per-Human is the open protocol Squillo uses to answer one question verifiably: who authorized this? When an agent posts a message or takes an action on a person's behalf, the action is provenance-stamped with an envelope shaped as a W3C Verifiable Credential 2.0, binding it to the human whose agent produced it. The stamp is applied where the action is cryptographically signed, so it cannot be stripped or bypassed through another entry point.

The protocol labels its own strength: a fully notarized stamp binds the human as the cryptographic principal; the machine-verified fallback is labelled as the weaker claim it is.

APH is an open standard: the specification and worked examples are published at github.com/squillo/aph. Why provenance must survive beyond any one vendor, and how to read a stamp, is covered at APH — Agent-per-Human.

Agent egress is guarded

Third-party coding agents ship with vendor telemetry: analytics and crash reporting that run on your machine and report elsewhere. Squillo's egress guard watches the outbound traffic of the agent harnesses it fronts and interrupts one class only: calls to the agent vendor's analytics and crash-reporting infrastructure.

The guard is allow-first. A request is blocked only when its destination matches, by exact agent-scoped match, an entry on a signed block-list — and only when the block can be enforced without touching anything else. Everything else passes untouched, including the agent's calls to its model. Where the guard cannot enforce safely, it observes and counts instead of interfering; its worst case is more permissive than intended, never less.

The guard is on by default. The default is governed like every regulation-sensitive behavior in Squillo: through regulatory localization, where a reviewed regulatory pack can adjust it for a jurisdiction.

What crosses a model boundary is scanned

Content that crosses a model boundary — what a model is fed, and what it writes to your files — passes through a sanitizer that looks for bytes meant to be read by a machine rather than the file's owner: prompt-injection carriers, provider watermarks, and fingerprints.

Invisible machine-readable carriers — hidden instructions a fetched page can smuggle past a human reader into a model's context — are stripped in both directions.

Some marks cannot be removed: a statistical watermark lives in a model's choice of words, not in any byte, so no byte-level tool can strip it. Squillo discloses that class rather than claiming to remove it.

Humans can watch, steer, and audit their agents

Squillo's control plane — local-only and key-gated on your machine — exposes agent work as an observable surface: a live activity stream, state reads, and event waits. Managed agents are spawned and steered through the same surface, so oversight and operation are one mechanism.

The same discipline extends across agent-to-agent boundaries: Squillo speaks the open A2A protocol. A peer agent's capabilities are declared in a card you can read before invoking it, and every invocation becomes a tracked task you can query or cancel.

With APH, accountability is checkable end to end: what an agent is doing is observable while it runs; who authorized it is stamped on the result.

The doctrine underneath

One rule governs this page and every page in this trust hub: a Squillo surface may only report a fact it has a mechanism to observe. Where the mechanism is absent, the output is the named absence, never the most convenient value. That is why the weaker provenance stamp is labelled weaker, the egress guard meters instead of guessing, and the sanitizer discloses the watermark it cannot strip.

Read next: APH — Agent-per-Human · Security · Privacy

Last verified: 2026-09-16

SquilloSquillo

Connect Anything. Automate Everything. Conecta cualquier cosa. Automatiza todo. Connectez tout. Automatisez tout.

Product Producto Produit

Get Squillo Consigue Squillo Obtenez Squillo For Enterprises Para empresas Pour les entreprises Book a Demo Reserva una demo Réserver une démo

Company Compañía Société

Careers Empleo Carrières Investor Relations Relación con inversores Relations investisseurs Press Prensa Presse

We're Hiring! ¡Estamos contratando! Nous recrutons !

Come join an innovative team that's snapping the world together. Únete a un equipo innovador que está uniendo el mundo, Snapp a Snapp. Rejoignez une équipe innovante qui assemble le monde, Snapp par Snapp.

See Openings Ver vacantes Voir les postes
Privacy Privacidad Confidentialité Terms Términos Conditions DPA DPA DPA Models Modelos Modèles Company Compañía Société Trust
Made with ❤️ in Indianapolis, IN Hecho con ❤️ en Indianápolis, IN Conçu avec ❤️ à Indianapolis, IN © 2021-26 Squillo Inc. All rights reserved © 2021-26 Squillo Inc. Todos los derechos reservados © 2021-26 Squillo Inc. Tous droits réservés