Security & safety

An AI on your PC should make you cautious. Good.

Handing your computer to any software — let alone an AI — deserves a hard look. That caution is exactly why we built Fixato the way we did: not to ask for your trust, but to make it so it can't misbehave in the first place. Here's precisely how.

It can't improvise. The agent chooses from a fixed list of named tools — it literally cannot run a command that isn't on the list.
You approve every change. Diagnosis is read-only; any repair needs your explicit yes, after a restore point is created.
Everything is reversible and logged. A restore point before, a full record after — all kept on your machine.
How a repair works

Every repair runs on rails.

Five guardrails stand between the agent and your system. Each one has to pass before the next.

1

Whitelisted tools only

The agent can't type commands. It picks from a fixed, published list of named actions — like run a system-file check or flush DNS. Anything outside that list is impossible, by design.

2

Read-only until you say otherwise

Diagnosis never changes anything. Fixato reads your system, reasons about it, and shows you what it found. Nothing is modified while it's just looking.

3

A restore point before system repairs — or they stop

Before any repair that touches Windows itself, Fixato creates a System Restore point. If it can't create one, that repair is blocked. Lighter cleanups are tightly bounded — and still ask first.

4

Your explicit yes, every time

Each change is a button you press, plus one Windows security prompt per session. No repair ever runs on its own, and nothing is done in bulk behind your back.

5

Verified, logged, reversible

Fixato checks the result before and after, and writes a timestamped log of everything it did — kept on your machine. If you're not happy, roll back the restore point.

One prompt, once per repair session. "Verified publisher" is your proof it's genuinely us — the app is Microsoft-signed.

Before that, you'll probably see a different box.

The first time you run the installer, Windows may show a blue notice headed "Windows protected your PC". That's SmartScreen, and it's about reputation, not safety: Windows extends trust to an installer once a lot of people have installed it cleanly, and Fixato is new. The file is signed and the publisher is verified either way — SmartScreen is saying "not enough history yet", not "something is wrong".

We'd rather you read that here than meet it cold. Click More info, check the publisher reads exactly Fixato Inc., then Run anyway. If it shows any other name, or "Unknown publisher", don't run it — tell us instead. The step-by-step version, plus how to verify the file's signature yourself, is on the download page.

Hard boundaries

What Fixato can't do.

These aren't promises we ask you to believe — they're limits built into how the agent works. It has no way around them.

Run arbitrary commands

No free-form PowerShell, no scripts it wrote itself. Only the audited, named tools.

Touch your personal files

It cleans temp and cache paths only. It never deletes your documents, photos, or folders.

Change the registry freely

Only a short list of documented, whitelisted keys — never a blank cheque to your registry.

Download and run programs

It can't fetch and execute external binaries. Nothing new gets installed without you.

Act without a trace

Every action is logged. There is no hidden mode, no silent change.

Send your files to the cloud

Only the diagnostic signals it needs — never your file contents without your explicit consent.

You're in control

The remote is always in your hand.

A human technician takes your PC to a back room. Fixato works in front of you: you see every check, you approve every change, and you can stop at any moment. Nothing on your PC is ever changed without you clicking to allow it — not by us, not by anyone.

  • You watch it work, step by step — no back room.
  • Closing the window parks Fixato in the tray. Quit from there and it stops entirely.
  • The only thing that runs on its own is a read-only check, every 6 hours. It can tell you it found something — at most once a week — and it can never repair on its own. Switch it off in the tray.
  • So that check survives reboots, Fixato starts with Windows — minimized to the tray, no window opens. Disclosed before you accept anything at install, and switched off in one click, same place.
  • Not happy with a repair? Roll back the restore point.
  • Every session is a plain-language log you keep.
  • Money-back guarantee if it doesn't earn its keep.

Your data stays minimal.

Fixato sends only what it needs to reason about your problem — diagnostic signals, never the contents of your personal files without your explicit consent. The detailed session report stays on your machine. Full detail in the privacy policy.

Found a security issue? Tell us.

We take reports about Fixato's security seriously and we read every one. Write to security@fixato.ai — it reaches a human directly, never an automated queue. Please include enough detail to reproduce what you found; we'll acknowledge your report, keep you posted, and credit you if you'd like once it's fixed. We ask that you give us a reasonable window to address the issue before disclosing it publicly, and that testing never involves other people's data or machines. Machine-readable version: security.txt.