The thread is the boundary
Cosmo starts with the conversation you are in, not every message, account, or detail in your life.
Cosmo needs context to coordinate effectively. The product makes that context understandable, limited, and easy to change.
Cosmo needs context to coordinate well. The product should make that context understandable, limited, and easy to change.
Cosmo starts with the conversation you are in, not every message, account, or detail in your life.
Preferences, plans, and loose ends are easy to review, correct, or remove.
Cosmo can prepare the work. Sensitive steps, like adding calendar events, ask before they happen.
When you ask Cosmo for help, Cosmo works from the thread, the people in it, and the context allowed for the request.
Every message you send in Cosmo is scrambled into a secret code the instant you hit send, and it only gets unscrambled on the screen of the person you sent it to. Even Cosmo’s own servers only ever see the locked version, never the actual words. We use Messaging Layer Security, the open IETF standard for end-to-end encrypted group messaging, so nothing in between your phone and theirs can be read by anyone else — not hackers, not us.
Locked workspace for AI work
Before Cosmo’s AI reads anything to help you, it strips out the personal stuff — names, phone numbers, addresses — like a censor blacking out details on a page before it’s shown to anyone else. Only after that cleanup does the message get looked at by the AI model that helps plan your day. That happens inside the Private Runtime: a walled-off space built specifically so your raw, personal information never touches the AI directly.
Cosmo turns repeated preferences, plans, and commitments into visible memory. You should be able to see what matters, fix what changed, and remove what no longer belongs.
Sarah is gluten-free.
Cosmo is pre-launch. The security model will become more visible in the product and in public documentation as each layer is ready.