How it works

The short version is on the front page. Here is the same picture, unpacked in more detail.

You sees and approves Your AI Assistant Frnd your gateway Your real services Mail Calendar Files … and more requests only what you allow

Scroll sideways to see the full diagram →

Your AI Assistant

Your AI Assistant connects to Frnd over MCP, the same way it would connect to any other tool. It never sees your mail password, your calendar credentials, or any other real secret — it only ever talks to Frnd, and only within the abilities you have turned on for it.

Frnd, the gateway

Frnd sits in the middle and holds your encrypted credentials on your behalf. Every request that comes through it — read this email, add this event, list these files — is checked against the permissions you have set for that ability before anything happens.

A request outside what you have allowed is refused at Frnd, before it ever reaches a real service. A request that needs your sign-off is held for approval instead of running straight through.

Your real services

Mail, calendar, files, and whatever else you connect — these are your actual accounts, reached only through Frnd. Your AI Assistant never talks to them directly, and never holds credentials for them at all.

You, in the loop

You decide what each ability is allowed to do, you can review everything your AI Assistant has done through the activity log, and turning an ability off takes effect immediately — Frnd simply stops honouring requests for it.

Follow a single request

Say your AI Assistant wants to send an email on your behalf. Here is what actually happens:

  1. The AI Assistant asks Frnd

    The request goes to Frnd, not to your mail account — your AI Assistant has no way to reach your mail account directly.

  2. Frnd checks what is allowed

    Frnd looks at the permissions you have set for mail. If sending mail is outside what you have allowed, the request stops here and a deny response is sent to the AI Assistant.

  3. Sensitive actions wait for you

    Coming soon

    Sending mail is the kind of action you may want to approve yourself. Once this lands, Frnd will hold requests like this and notify you before doing anything.

  4. Frnd carries out the action

    Once allowed, Frnd decrypts your credentials for the moment it takes to act, sends the email through your real mail account, then drops the decrypted key from memory again.

  5. It is logged

    What happened, when, and through which connection — so you can check, any time.

  6. Reply returned to your AI Assistant

    A reply with requested data is returned to your AI Assistant.

Ready to set it up yourself? Getting started guide →

Want the technical detail on how your credentials are encrypted? Read about security →