Skip to content

Your accounts and your work stay yours.

How a request moves through Oat.

You

The Desk, Studio or WhatsApp.

A verified sign-in sets workspace and role.

The Oat app

Every server action, with your role checked per call.

SQL pinned to one workspace under row-level security

Short-lived signed links, no public URL

Leased jobs that resume after a restart

Database

Every row carries its workspace ID.

Private object storage

Imports, images and exports, opened only by short-lived links.

Background worker

Research, drafting, checks, carousels and posting.

Draft and context, never credentials

Queries out, page text back as data

One approved post, sent once

Language models

Writing and checking, holding no secrets.

Web search

Research on the open web, refusing private addresses.

Your site and channels

Instagram, LinkedIn, X, Facebook, your Oat site, your newsletter and WhatsApp.

  • One workspace cannot see another.

    Every query is pinned to one workspace by row-level security in the database.

  • Models never hold your keys.

    A model can suggest an action, but the server decides the workspace, and publishing tokens never enter a prompt.

  • Secrets are encrypted.

    Tokens Oat holds are encrypted per workspace and deleted when you disconnect. Social accounts sign in on their own network.

  • An approval names one version.

    A changed piece needs approving again, a retry never posts twice, and Live means the network confirmed it.

  • Web pages are data, not orders.

    Fetched text and model output never run as instructions. Oat's check is advice, not proof of authorship or fact.

  • Actions are logged. Deleted data leaves.

    Approvals and changes are logged with who and when. Deleted data leaves active systems within 30 days, as the privacy notice sets out.

Found a problem? Tell us. Every vendor is on the subprocessors page.

See the Desk with your work in it.

Start free