Host: Most tech companies have a security page that's basically a long list of ways they're amazing at protecting you. But there's this one AI platform, MyOrbit, that did something pretty weird—they added a section explicitly stating what they do not claim.

Listener: Wait, they're actually advertising what they can't do? That sounds like a terrible marketing move. Why would they admit to that?

Host: It’s about being honest about the trade-offs. The big headline in that box is that MyOrbit does not offer end-to-end encryption or zero-access messaging. They flat-out say that they are technically able to access your message content.

Listener: Hold on. If I'm using an AI for personal stuff, that sounds a bit alarming. 'We can see your messages' isn't exactly a comforting slogan. Why can't they just lock it down so even they can't see it?

Host: Well, it’s a design choice. Think about what the platform actually does: it’s an AI that participates in your conversations and uses safety scanning in real time. If the system were truly 'zero-access,' the AI assistant wouldn't be able to read your messages to help you, and the safety tools couldn't catch abuse. You basically have to choose between a platform that is totally blind or a platform where the AI is actually useful and safe.

Listener: Okay, so it's the 'assistant' part. If the AI is going to act on my messages, it obviously needs to see them. But if they're not doing the 'zero-access' thing, what are they actually promising?

Host: They make three very concrete claims. First, everything is encrypted at rest using AES-256—that's the industry standard—and they use TLS 1.3 for data in transit. In plain English, your data isn't just sitting on a disk in readable form, and it's protected while it's traveling between you and their servers.

Listener: So it's not 'naked' on their servers, but they hold the keys to unlock it if they need to for things like support or legal requirements?

Host: Exactly. The second big one is about deletion. It’s not one of those 'submit a request and we'll get back to you' deals. You trigger the deletion yourself, and they claim it is 'real' and immediate. And thirdly, they don't train models on your data. They use external APIs for the AI, and whatever your AI 'twin' learns, it's strictly for your use, not for improving their global models.

Listener: That training part is huge. But I'm still stuck on the terminology. You mentioned 'encryption at rest' versus 'end-to-end encryption.' To a regular person, those sound almost identical. Is the industry just banking on us being confused?

Host: That’s exactly the point the report makes. A lot of AI companies use what they call 'privacy language'—phrases like 'military-grade encryption' or 'we take your privacy seriously.' It’s designed to make you feel like it's zero-access without them actually promising it. The rule of thumb here is: if the AI assistant is reading and responding to your messages, it’s almost certainly not end-to-end encrypted. They are protecting your data from hackers, but not from the platform itself.

Listener: So MyOrbit is just coming out and saying it because they'd rather have a 'weaker' true claim than a 'stronger' lie that eventually blows up in their face?

Host: Right. The philosophy is that trust built on a misunderstanding is just a liability waiting to happen. They want to make sure the promises they make are ones they can keep even on their worst day. The doc actually suggests that when you're looking at any AI product, you should skip the flowery adjectives and look for the box that says what they *don't* claim. If that box doesn't exist, that’s your answer right there.

Listener: It’s definitely a different way to look at a security page. I'll have to go back and actually read their full list of claims to see the fine print.

Host: It’s worth the read. The full security page on their site puts the claims and disclaimers side-by-side so you can see exactly where the boundaries are.