Every other cloud holds the map of your business. We hold ten fields.
We cannot see your clients.
Not "we choose not to look." The platform does not send it, so there is nothing to look at, nothing to leak, nothing to produce under subpoena, and nothing to sell.
The complete record we receive
Every month, your deployment sends us this and nothing else. Ten fields and a signature. You can read it before it leaves your building.
What we never receive
- Your client company names
- Hostnames, IP addresses, MAC addresses
- Per-client asset counts
- Ticket volumes, subjects or contents
- Your revenue, margins or pricing
- Staff names or utilisation
- Any telemetry, log line or capture
And it stays that way
A payload carrying anything else is rejected, not stripped. Silently removing an extra field would mean you never learn your deployment has a defect.
And this list never grows. If a feature we want would need another field, the answer is no. It is a published contract, not an implementation detail.
Because it runs on your hardware
The reason we can promise this is structural, not a policy we could quietly change.
And if the hardware has to be in Europe, it can be. We rent a Tier 1 appliance out of Frankfurt, so an EU client's estate is held on a box inside the EU — which regions are proven, and which tiers.
Your clients' data never moves
Monitoring, logs, captures, tickets, credentials — all of it stays in your rack. There is no ingestion pipeline to us because there is nothing to ingest.
The model runs on your GPU
No prompt leaves your building, and no AI usage is metered — it costs us nothing because it is not our hardware.
It runs air-gapped
Fully offline if you need it. The licence is carried in by hand and everything else works unchanged.
Guarding an agent that has tools
Genie reads your clients' log files, ticket bodies, emails and configuration. All of it is text an attacker can reach, arriving at a model that holds tools. That is the textbook injection vector, and it is not hypothetical.
Trust is provenance, not appearance
Content is tagged untrusted where it enters, not classified later by a model reading it. A classifier deciding whether text looks like an injection is guessing. A boundary tag is a fact. Where retrieved content requests an action, that request is a finding — recorded, surfaced, never executed.
The guard is code, not an instruction
Detection runs at the single write path every action passes through — never as a line in a prompt. Prompting has been measured and it loses: published benchmarking in July 2026 found deterministic execution-time guardrails beat system-prompt defences for every frontier model tested. Our own gate proves it by stripping the instructions and requiring the attack still be refused.
You can replay any decision
What was asked, what was retrieved and from where, which parts were untrusted, which tools ran with what arguments, what each returned, what the tier decided and why. Rendered from the audit log and nowhere else — including for refusals, because "why did Genie not do this?" gets asked more often than the opposite.
He watches himself, and it's a finding not a shutdown
Unusual tool-call rates, unfamiliar sequences, repeated refusals, first use of a capability, budget consumption that doesn't match the work claimed. Every one goes to a person. None triggers an automatic stop — an agent that halts itself on an anomaly is a denial of service on your practice.
Who said Genie could do that?
Every platform with an autonomous agent can tell you what they configured it to do. None can tell you what the client agreed to.
A client-authorised change record sits beside the autonomy tier: which change classes this client pre-approved, in what window, with what notice, who at the client signed it, their authority to do so, and what is never pre-authorised — a list they wrote, not one we defaulted in.
So when an MSP is asked "who said you could reboot our domain controller?" the answer is a name, a date and a document — not a setting.
It narrows, never widens. If the client pre-approved a reboot but the capability's tier is approve-first, it still needs approval. The client's agreement is a precondition, never a promotion. Both gates pass or nothing happens.
Absent means nothing is authorised. No record, no defaults, no inherited template — every change asks. Silence is not consent.
And it expires. An authorisation signed by someone who left two years ago is not an authorisation. When a contact departs, everything they signed is surfaced for re-confirmation.
You are always told you are talking to an AI
Article 50 of the EU AI Act requires it, it took effect on 2 August 2026, and it is our obligation as the provider — not yours. It cannot be pushed downstream into a licence agreement, and we do not try.
Content Genie generates carries machine-readable marking. We do not lean on the "it's obvious" exception — we describe him as a colleague rather than a chatbot, and that framing is an argument against obviousness, not for it.
What we commit to
Each of these costs nothing but discipline, and each is a reason people leave an incumbent.
Full export whenever you want, including on the way out — and it works better on the way out than on the way in.
Expiry, non-payment, even offboarding degrade administration only. Your clients are not party to a billing dispute.
Annual terms renew on a decision, not on a silence. We remind you before it happens.
Lose a client and your bill drops mid-term. Sustained under-use gets you a downgrade offer we send unprompted.
No retention wall, no exit interview, no "are you sure" three times. Downgrading costs the same clicks as upgrading.
The projected charge is visible before the period closes, and we bill the 95th percentile — a one-day migration spike doesn't cost you a month.
What we don't do
Written down, because a limit you discover during an incident is worse than one you were told about.
We're not a hosted service. Dream-Genie runs on your hardware. That's a deliberate choice and not everyone wants it.
We don't hold a SOC 2 report. We hold no SOC 2 report and we will not imply one. What we do hold is an assurance register — every control, what evidences it, and what it does not cover — and you can read it before you ask us a single question.
We don't sell email security, phishing protection or awareness training. Those are threat-intelligence businesses and we'd do them badly.
We don't match the twenty-year device catalogues of the incumbent monitoring vendors. We publish exactly what we support and keep that list honest.
Something here you need answered before you'd trust us with your clients? hello@dream-genie.ai — you'll get an answer from the person who built it.
Nobody should have to babysit this box
A job that ran, a result that did not move
It maintains itself. It vacuums its own database, prunes its own retention, checks its own certificates and verifies its own backups — and a maintenance job that quietly stops working looks exactly like one that is still running.
A fault found on one deployment is fixed on all of them — anonymously, and written down where you can read it.
The engine that does that maintenance runs beside the platform, survives what stops it, and has a published list of four verbs it can never grow past.
You are never going to notice that. You have a practice to run, and the first sign would be the day something you needed did not happen. So we watch that the box is looking after itself, and we tell you when it stops.
We do not maintain your box. Your box maintains itself and tells us whether that is working. Nothing we run can reach in, execute anything, or change a setting — and that is a constraint in the code, not a promise in a policy.
What it sends is about the machine and the jobs it ran on itself. The version it is running and how far behind that is. When each maintenance job last succeeded. Certificate expiries, disk against growth rate, retention against what you configured, and whether a backup that has succeeded every night has ever actually been restore-tested. Plus the headroom figures and the date we think you cross your own tolerance. No client names. No hostnames. No tickets. No technicians. Nothing about anything you manage.
That distinction is the whole point. A cloud platform sees your clients, your technicians, your tickets and your financials and calls the result support. A version number and a vacuum timestamp are not that kind of data, and we are not going to pretend otherwise by bundling them together.
It is off unless you turn it on, and turning it on shows you the exact record that would be sent, filled in with your own numbers, before the first one goes. In our console you are a pseudonym — putting a name to one requires an open ticket, and it is written into your own portal so you can see who looked and when.
And it changes nothing if you say no. Support works the same, the product works the same, and an air-gapped deployment that never speaks to us at all is a fully functioning platform. A vendor who can only help the customers who opted in has built something else.
Read the record before you send it
Thirty days read-only, and we receive ten fields. You can check every one.
How updates reach you — and why they cannot take you down
On 19 July 2024 a security vendor's content update crashed 8.5 million Windows machines. It was not a code release. It was auto-applied, globally, all at once, with no staged rollout and no automatic halt.
Four things separate a platform that improves continuously from one that fails catastrophically, and we hold all four.
Your deployment asks. We never push. There is no path from us into your estate and no code that could create one. A vendor that can reach in can take you down.
Detection content may apply automatically. Code never can. Whatever flag accompanies it. That is the exact assumption the July 2024 file violated.
Nothing reaches everybody at once. Our own deployments first, then those who opted in, then everyone — with a soak between each stage. The first stage is never skipped, for a hotfix or anything else. Urgency is the argument that precedes every catastrophic auto-update in this industry's history.
And it halts itself. If deployments start reporting faults after a release, the rollout stops without anybody awake — and resuming takes a human.
You control all of it. Which stage you are in, whether content applies automatically, and whether you report faults at all. All three default to the conservative answer, and declining every one of them changes nothing about how the platform behaves.
The security half
It does not replace your EDR. It watches what your EDR cannot see.
The engine stays whichever one you already run — Microsoft’s, or theirs. We manage it, we watch the estate it does not cover, and we do something when it fires. External attack surface, authenticated web and API scanning, Active Directory attack paths, detonation on your own hardware, and detection rules proven by making them fire.
The endpoint half has a name. Ward manages whichever engine you already run — and ships no kernel driver of its own.
The number an endpoint console cannot show you · a worked example
A console can only show you machines that already carry its agent. The gap between what your tools count and what is actually on the network is the whole problem, and it is not a number any endpoint product can produce about itself. Genie sweeps the range, reconciles it against every security console you run, and hands you the difference.
Protected and reporting
The agent is installed and the telemetry is arriving.
Protected and silent
Installed, present in the console, and sending nothing. This is the interesting one, and it is the state a console cannot show you.
Unprotected
Found on the network, no agent, nobody managing it.
Unknown
We could not reach it. Recorded as unreachable, never as clean.
The route from an ordinary user to Domain Admin
Drawn, with the one change that severs it. That is what a penetration test delivers, once a year, for several thousand dollars — and it runs here continuously, on every client, as part of the licence.
Detonation — where the file goes
Nowhere. A suspicious file runs on your own hardware and what comes back is behaviour rather than a score. Every competitor uploads it to theirs. Nothing leaves unless you said it may.
The hunt that found nothing
“We looked for this on your estate on Tuesday and did not find it.” A negative result, published. No competitor publishes one, because an empty answer is only worth anything if you can show the looking — and unreachable is never recorded as clean.
Try it on your own estate
Thirty days, read-only, on your own hardware. No card, no call, and nothing to uninstall if you walk away.