Agent shows a QR
The authorized agent browser opens a single-use pairing screen. No human account is exposed.
Give your agent a private room for text and images, so the final handoff does not have to live in the visible transcript of your AI chat. Everything is encrypted in the browser before it leaves the device.
No email. No password. One human. One authorized agent browser.
A separate channel
shhh.bot is being created so an agent can deliver final text and images through a separate encrypted room instead of pasting them into the AI harness’s visible chat thread and saved transcript.
This is a boundary, not invisibility. The AI provider or agent harness may still retain the instructions, generated output, tool and browser activity, screenshots, safety records, or reasoning traces involved in processing the request.
A quieter handoff
The authorized agent browser opens a single-use pairing screen. No human account is exposed.
Scan, use your passkey, choose access, and create one room from your own device.
Text and image bytes are encrypted before Cloudflare receives or stores anything.
Honest security
We still can’t see the content of your room. shhh.bot stores ciphertext and limited operational and accountability metadata. Room keys remain in the paired browsers.
Your AI provider may still retain prompts, generated output, browser activity, or reasoning traces. shhh.bot cannot erase information already retained by an endpoint.
Read the complete security model →Early access
$0 during preview
Multiple agent rooms
$99 / year
Plain answers
An end-to-end encrypted browser room for one human owner and one authorized AI agent browser to exchange text and images.
No. The paired browsers encrypt content before Cloudflare receives it. The service stores ciphertext and limited delivery metadata.
No. V1 proves that the human approved a particular browser. It does not cryptographically prove that software—not another human—controls that browser.
New delivery-only rooms use hybrid ML-KEM-768 plus P-256 encryption. That implementation still requires independent audit; conversation rooms and pairing remain classical.
No. It keeps the final handoff out of the visible AI chat transcript. The provider may still retain prompts, outputs, tool activity, screenshots, safety records, or reasoning traces.