# What cybee sees. What never leaves your Mac.

> What cybee sees on your Macs, what it sends to us, who approves a change and how a sealed record is checked. A Swiss company, hosted in Europe.

Page: https://cybee.ai/security/ (Security, data handling and permissions)

Security and privacy

cybee protects the Macs your team works on, so it has to see what runs on them. This page shows what it looks at, what it sends us, and who says yes before a Mac changes.

`curl -sSf https://get.cybee.dev | sh`

From get.cybee.dev, cybee’s install server. [Read the script](https://get.cybee.dev)

Run it in Terminal, a chat, your IDE or a CLI. Keep working where you started.

[Ask a data question](https://cybee.ai/talk-to-us/)

Figure: Illustration: detection, checks and fixes run on your Mac. Your files stay there, and so do saved passwords and tokens. cybee, hosted in Europe, receives security facts and recorded AI tool actions, and keeps a dated record. Your AI assistant, your alert channels and Google Workspace only take part when you connect them. Each connection has its own permissions and terms.

## You let it into every Mac. Someone will ask what it does.

Security software has to see what runs on a computer to protect it. So before you install it, and again when a client asks, you need to know where that access ends.

before you install

### You want to know what you are letting in.

“What exactly does this get access to?”

This page shows what cybee looks at and what it sends. [The install guide](https://cybee.ai/docs/install/) shows each thing macOS asks you to allow.

on day one

### Your team asks if they are being watched.

“Can my employer see my files?”

No. cybee watches programs, not people, and files stay on the Mac.

in a questionnaire

### A client asks which tools can reach their data.

They want it in writing: what leaves your Macs, and where it goes.

at a review

### An auditor asks who approved a change.

The dated record keeps the time the person at the Mac said yes.

## It works on the Mac. Changes wait for you.

Protection and the checks run on each Mac. cybee keeps a dated record of what it saw, and anything that would change a Mac waits for the person who uses it.

Built on Apple

### It runs on Apple’s own security framework. And Apple checked it for malicious content.

Apple checked cybee’s Mac software for malicious content before release. That check is called notarization. It is not a certification of how well a product detects threats.

To see what programs do as they run, cybee uses the part of macOS that Apple built for security software, the Endpoint Security framework.

[How Apple notarization works](https://developer.apple.com/documentation/security/notarizing-macos-software-before-distribution)

Figure: Four things you can check before you paste the command.

What it sees

### It sends a list of facts about your Mac. Never what is inside your files.

To catch bad software, cybee inspects program behaviour and content on the Mac itself. What reaches cybee is a list of facts: security events, which settings are on, which apps, extensions and AI agents are installed, and what cybee recorded the AI tools doing. A Swiss company. Hosted in Europe.

on every Mac

#### Protection and device settings

Program behaviour and content are inspected locally to detect threats. Protection, safer settings and responses run on the Mac. Security events, settings, app lists and alerts are sent to cybee.

Never sent: what is inside your files, or the passwords and tokens saved on the Mac.

AI tools

#### AI tools and recorded actions

Which AI tools are installed, what they are connected to, and what cybee recorded them doing. This record is sent to cybee. It can include the commands a tool ran and the names and locations of files, so a client name or a password typed into a command can appear in it. What is removed before it is stored is not final yet. Read it before you share it or paste it into a chat.

A separate view from the everyday security facts.

when you connect it

#### Google Workspace

Account events, which apps were given access to an account, downloads from Drive and changes made by an admin. Only the organisation you connect is included.

Never read: email and document contents.

services you choose

#### Your AI assistant and alert messages

Your chosen assistant processes your questions and summaries under its own settings and terms. Slack, Teams or SMS providers handle the alerts you share through them, under their terms.

You choose which of these services to connect.

Not final yet

Five things are not final yet: the exact list of what is sent, what is removed from recorded AI tool actions, how long data is kept, which other companies handle it, and the data processing agreement. You can ask for the current agreement and the current details today: [hello@cybee.ai](mailto:hello@cybee.ai).

Who decides

### A request in the chat. A decision on the Mac.

When someone asks their AI assistant to change a setting, the person who uses that Mac sees the request on it, in plain words, and says yes or no. Nothing changes before that. If they say no, the setting stays as it is.

Stopping bad software happens straight away, without asking anyone. Changing a setting always waits for a yes on that Mac. An alert never approves a change on its own.

[Read the assistant guide](https://cybee.ai/docs/assistant/)

09:41

09:42

Figure: The person at the Mac decides. The record keeps the time.

The record Proof plan

### A record your client can check. The check shows if it was changed.

When you send a Trust Passport, the person who receives it can open one link and compare it with the copy cybee sealed. If anything in it changed after sealing, the check shows it.

The check answers one question: has this record changed? It is not an independent audit, a company certification or proof about anything that was not assessed.

[How the Trust Passport works](https://cybee.ai/docs/trust-passport/)

Figure: What the check answers. It says nothing about what was not assessed.

## Free for every Mac. You pay when you need to prove it.

The protection is free because we want every Mac in a small company protected. We earn money when a company has to prove it.

### Free

Free

Forever. Unlimited Macs and people.

- Stops bad software while it runs

- Alerts in macOS, Slack, Teams and SMS

- 118 safety checks on each Mac

- Apps, extensions and AI agents listed

- “Am I safe?” answers in your AI assistant

- Google Workspace account activity

- Email support within one working day

[Start free](https://cybee.ai/docs/install/)

### Proof plan

CHF 9 per Mac per month, or 90 a year

Everything in Free, plus:

- Weak settings fixed and kept fixed

- The sealed Trust Passport

- Security training, completion recorded

- Incident response plan

- Chat support

[Install, then start the 14 day trial](https://cybee.ai/docs/install/)

The 14 day trial starts in your AI assistant, after cybee is installed. Ask for a Proof plan feature, such as the Trust Passport. The link arrives in the chat and leads to Stripe, the payment service.

Per Mac, excluding tax. The same number in CHF, EUR, USD and GBP. Runs on Macs with an Apple chip, M1 or newer. Macs with an Intel chip are not supported. To check a Mac, open the Apple menu and choose About This Mac. [All plan details](https://cybee.ai/pricing/)

## Before you connect.

**Q:** What does cybee not do?

It does not send what is inside your files, or the passwords and tokens saved on the Mac, anywhere. It is not a certification or an audit, and it does not answer for your policies, your people or your cloud. It runs on Macs with an Apple chip, M1 or newer. Windows, Linux and Microsoft 365 are not supported today. They are being built. Choosing what each AI agent may reach is planned, not live.

**Q:** Is this employee monitoring?

cybee is security software. It is not built to track productivity or judge employee performance. Some of what it records can be tied to a person, so here is the full list: which settings are on, which apps and browser extensions are installed, what a program did when it behaved like malware, and what AI tools did on that Mac. If you connect Google Workspace, account events and Drive download events are added. It does not read your messages or your browsing. Tell your team what it records before you install it.

**Q:** Does cybee control every AI agent?

No. Installed tools, configured connections and recorded activity give you visibility. Limits on the credentials each agent can use remain planned.

**Q:** How does cybee handle what it keeps?

Every fact it keeps carries the date it was seen. The device IDs and access keys that cybee itself issues are stored hashed, a one way scramble, so they are not kept as readable values. If you paste a client’s questionnaire into the chat, cybee reads it as text. It does not follow instructions written inside it. How long data is kept and when it is deleted is not final yet, so ask us for the current details.

**Q:** Where can I request processing information?

Write to [hello@cybee.ai](mailto:hello@cybee.ai). Ask for the current data processing agreement and the details relevant to your setup. The [privacy policy](https://cybee.ai/privacy/) explains how personal information is handled.

## Where to go next.

[Privacy Policy How personal information is handled, in full.](https://cybee.ai/privacy/) [Install guide Set up your first Mac, step by step.](https://cybee.ai/docs/install/) [Trust Passport guide What the record covers, and how a recipient checks it.](https://cybee.ai/docs/trust-passport/) [AI agents See what each AI tool on your Macs is connected to.](https://cybee.ai/product/ai-agents/) [About cybee The Swiss company and the people behind it.](https://cybee.ai/about/) [Talk to us Ask about data handling before you connect a Mac.](https://cybee.ai/talk-to-us/)

## Your next client will ask. Be ready.

`curl -sSf https://get.cybee.dev | sh`

Run it in Terminal, a chat, your IDE or a CLI. Keep working where you started.

Free for every Mac with an Apple chip · Asks before it changes your Mac [What it installs](https://cybee.ai/docs/install/#see) [Read the install script](https://get.cybee.dev)
