SECURITY MODEL

How Jim stays on your side of the table.

Because Jim can act, the safety has to be real code — not a disclaimer. Here is exactly how it works, in plain English. Where something is still rolling out, we say so.

APPROVAL MODEL

He proposes. You approve. Per trade.

Jim drafts a typed order from your words and stops. Nothing executes from free text. You authenticate, then approve each order — the agent has no path to act on its own.

GUARDRAIL ENGINE

Deterministic limits, enforced before a venue.

A code-based engine checks every order against the limits you set — concentration, leverage, order size — before anything could reach a market. These are real checks, not a disclaimer. The core is open; read it.

CONNECTION & CUSTODY

Your brokerage, your login, revocable.

When real-money execution rolls out, you authorize Jim through your broker’s official connection flow. Jim is designed so it cannot move assets without your own authenticated, per-trade approval — we treat technical access as custody and architect against it. You can cut the connection any time.

Today: research only — no connection at all. The agent is coming soon.

RECORDKEEPING

Every order and decision, logged.

Orders, approvals, and declines are kept with your stated reason in an append-only log — the basis for honest review and aligned with SEC Rule 204-2 thinking.

VOICE CONSENT

Inbound by default. Outbound only with written consent.

The public number is inbound — you call Jim, and it’s a guided demo that won’t touch a real account. Proactive AI calls happen only with your prior written consent (required by law), identify themselves as AI, and you can opt out anytime.

OPEN CORE

Inspect it yourself.

Jim’s core — the guardrail engine and execution path — is open source. The most honest security claim is one you can read.

Trust is the product.

Get access