Your rules
Define which data may be used, which destinations are permitted and which actions must remain blocked.
AI protection against AI attacks
We are developing AI-Certain as an independent control layer between AI assistants and the data, applications and APIs they want to access.
This interface is a demo. Technical protection will depend on the security core and verified integrations.
An AI assistant can analyse information and propose actions. AI-Certain is designed to check whether a requested action fits the task, which permissions apply and what data would leave the system.
Our security approach combines technical boundaries with decisions you can understand. Critical actions are held or blocked. Approval stays with the user wherever their rules require it.
These building blocks guide our development.
Define which data may be used, which destinations are permitted and which actions must remain blocked.
Give each assistant a specific task with appropriate permissions, a time limit and a cost limit.
Choose models through supported integrations and divide tasks between assistants with separate roles.
Review the exact action and its effects. Each approval is intended to apply once to that specific action.
Stop one or all assistants using a visible button or your personal stop phrase through your authenticated control channel.
Track what was requested, allowed, held or blocked, with clear reasons.
Example task: “Review tomorrow’s reservations.”
Choose an action to see the intended decision.
The assistant may read the required reservations. Access remains limited to the defined scope.
AI-Certain is being developed at AI-Ideenschmiede. We combine human experience with AI as a tool and review the results of our work.
Our goal is an understandable security solution with technically enforced rules. A second AI can provide additional insights. Binding access limits are intended to be enforced by the independent security core.
More about AI-IdeenschmiedeRules, permissions, models, approvals and emergency stop controls have been developed as a concept and interactive demo.
Check actions on the server and execute them under control. Permissions and stop controls must be enforced independently of the assistant.
Test permitted and prohibited actions, manipulation attempts and failures. Use those results to build further integrations.
The shared security core and management interface for connected AI assistants and systems.
The same approach, with rules and interfaces for AI features within AILENDO. The user stays in control.
We are still in development. The integrated interface demonstrates the controls using sample data. It is not connected to an AI model or production system and does not block real attacks.
We focus on controlled AI actions: manipulated content must not give an assistant extra permissions. AI-Certain is designed to enforce the user’s boundaries independently of the model. This does not require identifying an attack as “AI-generated”.
That is planned. Assistants can be assigned different models and roles. Communication between them is intended to follow the same data and permission rules. Supported models will be determined through verified integrations.
The planned stop blocks new actions. Cancelling an action already in progress depends on the relevant interface. Data already sent and actions already completed cannot be reversed by the stop.
Protection is planned for actions routed through controlled integrations. Each integration requires its own technical verification. Websites, servers and user accounts also require standard security measures against general attacks.
A release date and price have not yet been set. Distribution is planned through Ailorium. The demo is free to explore.
Choose models, draft rules and tasks, review an approval and test the emergency stop. Everything runs locally with sample data. Settings are temporary and do not enforce real security rules.
AILENDO assistant · Reservation R-1042
5 October 2026
10:00 → 11:00
Recipient outside permitted destinations. This action is outside the task’s scope.
Switching providers requires appropriate permission to share data. In a future implementation, keys will be stored securely on the server.
In the planned product, written rules will be translated into verifiable settings and confirmed by you before activation.
5 October 2026 · 10:00 → 11:00
In the planned product, the stop phrase will only be accepted through your authenticated control channel. Documents and third-party messages will not be able to trigger it. This demo does not implement authentication.
Explore the interface and see how rules, approvals and stop controls are designed to work together.