How Jim stays on your side of the table.
Because Jim can act, the safety has to be real code — not a disclaimer. Here is exactly how it works, in plain English. Where something is still rolling out, we say so.
He proposes. You approve. Per trade.
Jim drafts a typed order from your words and stops. Nothing executes from free text. You authenticate, then approve each order — the agent has no path to act on its own.
Deterministic limits, enforced before a venue.
A code-based engine checks every order against the limits you set — concentration, leverage, order size — before anything could reach a market. These are real checks, not a disclaimer. The core is open; read it.
Your brokerage, your login, revocable.
When real-money execution rolls out, you authorize Jim through your broker’s official connection flow. Jim is designed so it cannot move assets without your own authenticated, per-trade approval — we treat technical access as custody and architect against it. You can cut the connection any time.
Today: research only — no connection at all. The agent is coming soon.
Every order and decision, logged.
Orders, approvals, and declines are kept with your stated reason in an append-only log — the basis for honest review and aligned with SEC Rule 204-2 thinking.
Inbound by default. Outbound only with written consent.
The public number is inbound — you call Jim, and it’s a guided demo that won’t touch a real account. Proactive AI calls happen only with your prior written consent (required by law), identify themselves as AI, and you can opt out anytime.
Inspect it yourself.
Jim’s core — the guardrail engine and execution path — is open source. The most honest security claim is one you can read.