What “private” actually means (and what it doesn’t)
Tuesday, 9:14am. Maya — ops lead at an 11-person ecommerce brand — needed a return status from Shopify. She opened the team’s shared AI chat, typed the store URL, and… hesitated with the password. Then she pasted it anyway. Forty seconds later she deleted the message. The tab history did not delete with it.
That hesitation is the whole topic. Teams shop for a private AI assistant for teams the way they shop for headphones: by the adjective on the box. Private. Secure. Enterprise-grade. None of those words tell you where the browser session lives, who can replay the transcript, or whether the agent still holds a logged-in cookie at 2am.
Here’s the uncomfortable part: most SMBs do not need a SOC 2 slide deck to make a good decision. They need five plain questions and a bias toward boring answers. This post is that checklist — security basics without the enterprise sales call. If you want product depth on how CloudyBot’s parent frames the isolated cloud computer, bridge up to the CloudyBot overview on CloudAxis. For signup intent, stay here and try the dashboard free.
The three places trust actually breaks
Security theater loves network diagrams. Real failures in small teams look smaller.
1. Shared chats that become shadow password managers. Someone pastes an API key “just this once.” Six people still have the thread. Nobody rotates the key. The AI product is blamed later; the ritual was the leak.
2. Browser sessions without a boundary. An agent that can log into Stripe is useful. An agent whose session is indistinguishable from a shared laptop profile is a different risk class. Ask where the session runs, how long it persists, and whether teammates inherit it.
3. “The vendor is big, so we’re fine.” Brand size is not a control. A consumer chat product optimized for viral sharing is not the same threat model as a hosted assistant with workspace isolation and hard caps. Size without boundaries is just a bigger blast radius.
Micro-story with numbers: a five-person agency we talked to spent 90 minutes drafting an “AI security policy.” It banned public ChatGPT for client work — and said nothing about where scheduled browser duties store cookies. Policy theater. The cookie question would have taken twelve minutes.
Five questions to ask before any agent browses logged-in
Print this. Bring it to the vendor call. Or skip the call and answer it from docs.
- Where does the browser session live? Local laptop? Shared vendor pool? Per-workspace isolated cloud browser? You want a clear answer in one sentence. CloudyBot’s product lane is a real cloud browser for agent work — OS-level isolation detail lives on CloudAxis; signup and duties live on how it works.
- How are credentials handled? Pasted into chat? Saved in a credential store? Ephemeral per run? Prefer vaulted secrets the model sees only when a duty needs them — not forever in transcript history. Read the plain-language take on privacy.
- Who can see this workspace? Seat model, invite model, admin visibility. “Private AI assistant for teams” fails if every contractor inherits every thread by default.
- What happens when we hit the usage ceiling? Metered products keep spending. Hard caps pause. That is a security-adjacent control: runaway loops should stop, not silently drain a card. See hard caps vs pay-per-use and live numbers on pricing.
- Can we revoke a session today without emailing support? If an ex-contractor still has a live browser login in the agent, you need a kill switch you control — not a ticket queue.
Insider stance you can disagree with: for a sub-20 person company, these five beat a 40-page security questionnaire. Questionnaires are how enterprise buyers feel safe. Checklists are how operators stay safe.
Comparison: consumer chat vs shared seat vs hosted agent workspace
Same model family can sit in three very different risk shapes.
| Shape | Session boundary | Credential habit | Best fit |
|---|---|---|---|
| Consumer chat | Personal account; weak team boundary | Paste-into-prompt culture | Drafting, not logged-in ops |
| Shared team seat | Better billing; still chat-shaped | Shared threads amplify leaks | Internal Q&A, light research |
| Hosted agent + cloud browser | Workspace-scoped browser & files | Vault / duty-scoped access (when designed that way) | Scheduled ops, monitoring, form work |
If your work is “summarize this doc,” consumer chat is fine. If your work is “log in, check the competitor price, write the brief,” you are in agent territory — and the agent vs chatbot for operations distinction matters for ROI and for blast radius. Hosted vs self-hosted is a separate fork; the honest tradeoffs are in hosted AI assistant vs self-hosted agent.
A 30-minute security basics playbook for SMBs
No counsel required. One founder or ops lead. Timer on.
- Inventory the agents (5 min). List every AI tool that can see customer data, billing, or admin logins. Include “temporary” ChatGPT Plus seats. Temporary is how permanent leaks start.
- Ban paste-for-login (5 min). Write one rule in the team doc: credentials go in the product’s secret store or a password manager handoff — never in a prompt. If the tool cannot do that, it does not get production logins.
- Pick one production workspace (5 min). Not five overlapping experiments. One place for duties that touch live sites. Chaos multiplies session sprawl.
- Scope the first duty narrowly (10 min). Read-only competitor URLs before anything with purchase power. Expand after a week of clean runs. Trust is earned in boring repetition.
- Schedule a revoke drill (5 min). Pick a Friday. Practice removing a seat and killing a browser session. If you cannot find the button, you do not have a control — you have a hope.
Where CloudyBot fits this playbook: start free on the dashboard, keep ceilings honest on pricing (Free to try; Growth $29, Pro $59, Max $199 — paid plans bill immediately and pause at hard caps), and read the human-facing promises on trust plus the data practices on privacy. For vulnerability reporting and security contact paths, see security.
Friction we will own out loud: no hosted assistant makes reckless credential sharing safe. Product boundaries help. Human habits decide. If your team keeps pasting Shopify passwords into group chats, fix that first — the model is not the villain in that story.
FAQ
What makes a business AI assistant “secure” for a small team?
Clear session boundaries, credential handling that does not depend on chat history, workspace access control, and a revoke path you can use without a support ticket. Certifications can come later; these basics come first.
Should we allow an AI agent to browse logged-in admin sites?
Only after you know where the session lives and how to kill it. Start read-only. Keep purchase and payout powers human until the duty has a clean track record.
Is a private AI assistant for teams the same as self-hosting?
No. Self-hosting can increase control and ops burden. A hosted private workspace can isolate sessions without you running the gateway. Compare tradeoffs in our hosted vs self-hosted guide before you buy servers to feel safer.
How do hard caps relate to security?
They limit runaway automation spend and force a pause when something loops. That is not encryption — it is blast-radius control for money and for noisy failure modes.
Where should we start with CloudyBot?
Open the dashboard on Free, connect one narrow duty, and review privacy / trust before you store production credentials. Upgrade when limits bite — paid plans bill immediately.
Further reading
Ask the session question first. Then try a hosted assistant with hard caps — Free to start, pause-at-ceiling billing when you upgrade.
Open the dashboard →