Oat keeps your archive, your accounts and your approval yours.
Oat holds your writing and your accounts, so one workspace never sees another and nothing leaves without a person's approval.
You
The Desk, WhatsApp or Apple Messages.
A verified Clerk session sets workspace and role.
Next.js on Vercel
Every server action, with your role checked per call.
SQL pinned to one workspace under row-level security
Short-lived signed links, no public URL
Leased jobs that resume after a restart
Neon Postgres
Every row carries its workspace ID.
Private object storage
Imports, renders and exports, deleted with the workspace.
Worker on Railway
Research, drafting, Dollop's checks, renders, publishing.
Draft and context, never credentials
Queries out, page text back as data
One approved revision, token used once
Vercel AI Gateway
The writer model and Dollop, holding no secrets.
Tavily
Web research, refusing private addresses.
Your site and channels
WordPress, Vercel, GitHub, LinkedIn, Instagram, YouTube, HeyGen, WhatsApp, Apple Messages.
- 01
One workspace cannot see another.
Every query runs as a database role that cannot bypass row-level security, pinned to one workspace, so even an unfiltered query returns only that workspace's rows.
- 02
The server decides what a model may touch.
Workspace and role come from the verified session, so a model or a chat message can suggest an action but never name the workspace, and publishing tokens never enter a prompt.
- 03
Every connection is encrypted for one workspace.
OAuth tokens, Application Passwords and deploy hooks are encrypted with AES-256-GCM under a server-only key, so the Desk shows the account and never the secret, and disconnecting deletes the ciphertext.
- 04
An approval names one revision and one destination.
A changed piece needs approving again, every publish is recorded as an intent first so a retry never posts twice, and Live confirmed appears only after Oat reads the result back.
- 05
Oat treats fetched pages and model output as data.
Fetched text and model output are quoted as data and never run as instructions, so only a person's action changes policy or publishes. Dollop, Oat's checker, runs on Jev by TypeSafe AI, and its score says nothing about authorship or fact.
- 06
The audit trail lasts 90 days and deleted data stays deleted.
Every edit, approval and publish is logged, a deleted piece cannot be restored by a retry, and data leaves active systems within 7 days and backups within 30, as the privacy notice sets out.
Security reports reach a person.
Write through the contact page with Security as the reason, and a good-faith report gets a good-faith answer. The subprocessors page lists every vendor.
See the Desk with your archive in it.
Request accessAccess starts with a conversation about what Oat may touch.

