Security Architecture
How Hands guarantees complete data sovereignty by executing entirely on your local machine.
Unlike cloud-based RPA (Robotic Process Automation) platforms that require you to pipe sensitive data to their servers, Hands is fundamentally designed around the principle of Local Execution. This document explains the architecture that makes it safe for use in highly regulated environments.
No Cloud VMs
Execution happens directly in your browser tab. We do not spin up remote Virtual Machines to browse on your behalf.
Local Authentication
Because it runs locally, you do not need to share auth cookies or session tokens with us. You are already logged in.
Zero Telemetry
We do not track which websites you visit, what you click, or what data the agent extracts.
100% Open Source
The core extension is open source, allowing your security team to audit the code and verify our zero-data claims.
How Data Flows (BYOK Mode)
When using the Bring Your Own Key (BYOK) mode, the data flow is completely decentralized:
- DOM Parsing: A content script running locally in your active tab parses the DOM and translates it into an accessibility tree.
- Sanitization: The extension filters out unnecessary visual noise.
- Direct API Request: The extension makes an HTTPS request directly from your IP address to your chosen provider (e.g., OpenAI). The Hands backend is not in the middle.
- Execution: The LLM returns an action (e.g., Click button X), and the content script executes the JavaScript event locally.
Compliance
Because Hands acts simply as a local tool (similar to how Google Chrome Developer Tools operates locally), it drastically simplifies compliance for enterprises. You do not need to sign a BAA (Business Associate Agreement) or Data Processing Agreement (DPA) with us when using BYOK, because we do not process your data.
All of what is happening is executed right in front of you, on your own machine.