---
title: "How We Protect Your Double: Security & Guardrails"
description: "Your knowledge and your voice are the two most personal things you can hand over. Here is every layer of guardrail that sits around them."
url: https://thedouble.ai/blog/how-we-protect-your-double
---

1.  [Home](https://thedouble.ai/)
3.  [Blog](https://thedouble.ai/blog)

[News](https://thedouble.ai/blog/category/news)

# Security, Safety, and Guardrails: How We Protect What You Put Into Your Double

Your knowledge and your voice are the two most personal things you can hand over. Here is every layer of guardrail that sits around them.

[Sahith Krishna](https://thedouble.ai/authors/sahith-krishna)3 August 20268 min read

Creating a Double means handing over two of the most personal things you own. Your knowledge, which took years to build, and your voice, which is how people recognise you.

We take that seriously to the point of being fanatical about it. Security is not a feature sitting somewhere inside The Double. It is the shape of the whole system.

Every request that moves through a Double passes a safety check before it goes any further. Guardrails sit at every layer:

-   **The intent engine**, which decides what a request even is
-   **Knowledge**, which controls what a Double can draw on
-   **The language model**, which controls what it can say
-   **Voice**, where a wrong answer carries the most weight
-   **Skills and actions**, where things happen in the outside world
-   **Workflows**, where several actions chain together
-   **Your own custom rules**, written by you, on top of everything above

Here is how each one works.

## **Guardrails at every layer, not in one place**

Most systems treat safety as a filter at the end. Something is generated, something checks it, and it goes out.

We built it as a funnel instead. A request enters, and at each stage it has to pass the guardrails for that stage before it reaches the next one. Intent is checked before knowledge is searched. Rules are applied before a response is generated. Permissions are confirmed before an action is carried out.

The reason is simple. By the time a system is deciding whether to send an email, it has already made a dozen smaller decisions, and any one of them could have gone wrong. Checking only at the end means catching problems late, if at all.

## **System guardrails: what every Double refuses**

Every Double on The Double carries system-level guardrails that its owner cannot switch off. These handle the categories where a confident wrong answer does real damage.

A Double should not give financial advice or health advice. It should not invent pricing, policies, timelines, or commitments that do not exist in its knowledge. It should not make claims on behalf of a person that the person never made. It should not turn uncertainty into confidence because the visitor clearly wants an answer.

When a Double cannot answer something safely or accurately, the correct behaviour is to say so and point the person to the right next step.

This matters most in voice. A wrong answer in text is a bad answer. A wrong answer spoken in someone's own voice sounds like that person saying it, which carries far more authority than it has earned. The more human the interface becomes, the harder the boundaries have to hold.

## **Your own guardrails, written by you**

System guardrails handle the universal risks. Everything specific to you is yours to define, and you write it in the same place you define your persona.

You can add your own rules as a prompt, in plain language, and they sit on top of the system guardrails rather than replacing them. There is no special syntax to learn.

This is where a Double stops being generic. A public speaking coach can say that anything outside communication and delivery should be redirected rather than answered. A founder can say the Double never discusses funding. A consultant can say it never estimates a project price without a call.

The system stops a Double from doing something dangerous. Your rules stop it from doing something that is simply not you.

## **A Double knows what you gave it, and nothing else**

Everything in your knowledge base, your skills, and your workflows is available to your Double. That is the full scope of what it knows, and it is drawn entirely from what you put there.

Which means the decision that matters is made by you, before any conversation happens. If something should not be used in answers, it should not be added. If it is added, your Double can use it.

The limit works in the other direction too, and this one gets overlooked. A Double does not go out to the internet to find things. It cannot search the web for an image, pull a video it likes the look of, or locate a document that seems relevant and present it as yours.

Everything it shares comes from somewhere you put it:

-   The knowledge base you built
-   The files, images, and links you uploaded
-   The videos you added
-   The skills and workflows you configured

If you did not give it to your Double, your Double does not have it. That is a deliberate limit, and it is the difference between a system that represents you and a system that improvises on your behalf.

## **Skills: permission by permission**

A Double becomes genuinely useful when it can act. It can share a document, capture lead details, ask qualification questions, book a meeting, send an email, or update a record in a connected system.

Every one of those is switched on by you, and the control is finer than on or off.

Take meetings. You can enable booking without enabling cancellation or deletion. Turn on booking only, and booking is all it will ever do, no matter how a visitor phrases the request. The same applies across skills. Which image it may share, which video it may show, which document it may send.

The point is not that some actions are too risky to enable. It is that you decide the exact shape of each one, and your Double stays inside it. Connect your inbox and allow sending, and it sends. Allow it to share three specific documents, and those are the three it will ever share.

Skills are controlled abilities rather than open-ended powers. A Double should know what it can do, when it may do it, and what it must never do without you.

## **Workflows and connected tools**

Workflows chain several actions together, which makes them powerful and also raises the stakes. One wrong assumption early on affects everything that follows.

So every node in a workflow carries its own guardrail rather than the workflow being approved once at the start. Before collecting information, the Double should know why it needs it. Before sharing a resource, it should pick the right one. Before booking, it should confirm the person actually wants that. Before writing to a connected system, it follows the permissions you set.

This matters more once tools are connected. When a Double can reach a CRM or a Gmail account, every step that touches those systems is checked against what you allowed rather than against what the tool makes technically possible.

Escalation is part of the same design. When a request is sensitive, unclear, unusual, or needs a decision the Double should not be making, the right outcome is to stop and bring you back in. A workflow that cannot pause is a workflow waiting to cause a problem.

## **People should know they are talking to a Double**

A Double represents someone. It does not pretend to be them.

That distinction has to hold in the product rather than in a policy page. A visitor should understand that they are speaking with an AI representation of a person, and a Double should never claim to be the human directly, however convincing the voice becomes. The goal of cloning someone's voice is presence, not deception.

The same respect applies to what a Double asks for. It should not demand a name and email the moment somebody shows a flicker of interest, and it should not collect information it has no use for. Understand what the person needs, help them with it, and ask for details when there is an actual reason to.

Trust is not only about protecting information once you hold it. It is about collecting it decently in the first place.

## **Why open source and self-hosting matter here**

A lot of AI companies build on closed models. You cannot see what is inside them, you cannot verify how they behave, and you have to take the vendor's word for where your data goes.

We fine-tuned an open-source voice model and self-host it ourselves. We could have used an existing voice provider and shipped faster. We did not, and the reason was open source, security, and transparency.

Self-hosting on its own does not make a system secure, and we would rather say that plainly than dress it up. What it does give us is control over where processing happens, how the model is deployed, and which outside companies are involved in handling your voice at all. Your voice sample is the most sensitive thing you give us, and we wanted to know exactly where it lives.

## **Deleting everything means everything**

You can delete your account whenever you want, and when you do, it goes.

We do not keep a quiet copy. We cannot restore your account afterwards, and that is not a limitation we are apologising for, it is the intended behaviour. A delete button that leaves things behind is not a delete button.

The same principle runs through the rest of the knowledge layer. Your material is stored separately from any model rather than trained into it, so removing a source removes it from what your Double knows straight away.

## **What we will never compromise**

There is one commitment here that does not move. Security and privacy come first, in everything we build and however the company grows.

We also keep improving it constantly. Every new capability is examined for what could go wrong before it ships, and its guardrails are built alongside the feature rather than added afterwards. That is how a system stays safe as it grows rather than trying to catch up later.

The whole product depends on being trusted with someone's knowledge and someone's voice. There is no version of success here that involves being careless with either.

A Double is powerful precisely because it represents you. That is exactly why it has to be safe.

[Sahith Krishna](https://thedouble.ai/authors/sahith-krishna)

Founder & CEO

## Keep reading.

[All posts](https://thedouble.ai/blog)

[

News

### Introducing The Double

Knowledge moved from elders to books to search engines. The person kept getting left behind. The Double is our attempt to bring them back.

03 Aug 2026

](https://thedouble.ai/blog/activate-yourself)

[

News

### What Is an AI Double, and How Is It Different From a Chatbot?

A chatbot answers on behalf of a product. A Double represents a person, in their voice and their knowledge. Here are the six layers behind it.

03 Aug 2026

](https://thedouble.ai/blog/what-is-an-ai-double)

[

News

### What an AI Double Can Actually Do Today

Answer questions, present your deck, share files, qualify people, book meetings, update your CRM. All inside a conversation, in your own voice.

03 Aug 2026

](https://thedouble.ai/blog/ai-double-capabilities)
