LIVE DEMONSTRATION

The company that runs this app cannot read what you type into it.

Below: Onyx, a real open-source enterprise AI assistant, running live under Ember Sovereign Mode — with proof a security team can check.

anydomain.example OPEN ↗

FRAME PENDING A GOVERNED RELEASE

Onyx ships with clickjacking protection on, so its current configuration refuses every frame — including ours. Loosening it is a measured release the owner must approve with a security key. When that lands, the change appears on the trust page and the app appears here.

OPEN THE LIVE APP →
Sovereign Mode

HOW THIS COMPARES

THE USUAL WAY
vendor’s cloud
RUN IT YOURSELF
your servers
SOVEREIGN MODETHIS PAGE
Can the vendor’s company read your data? Yes — technically possible Depends on support and telemetry No — hardware and key enforced
Where it runs The vendor’s cloud account On your cloud account or computer An attested confidential VM
Who controls updates Vendor-controlled Customer-controlled and maintained Owner-approved, recorded on-chain
Where your data can go Vendor-controlled Your firewall; telemetry varies One approved list; the rest blocked
How you check the claims Audits and contracts Your logs and your network A live check anyone can run
Who operates it The vendor You The vendor operates; the owner governs

Allow-listed providers receive what is sent to them — this deployment permits api.anthropic.com.

This page certifies what is running and that it was approved — not what the application does with it. The method is public: the whitepaper · the trust page.