Life GPS Try the beta

Every digital system has a security layer. Your life has no one of its own.

Status: public draft · the long version — prior art, the full map of interactions, requirements and sources — is being prepared at /security-model/review · found a flaw: /security

In short

Security already runs the digital world. But who is protecting your life?

Your phone protects itself. Your bank protects the money. The AI company protects the model. None of them holds your side — the one place where all of it lands: your time, your money, your attention, your decisions, your next step.

You would never give every shop the password to your bank account so it could decide what is right for you. The shop asks your bank for one decision. It does not receive the account behind it. We think the rest of your digital life needs the same boundary.

We are building a human operating system, and we think its security model has to be written for the person, not borrowed from the systems around them. This page says why, what that model is, and — as honestly as we can — how much of it exists today.

Security already decides what everyone is allowed to do

Some forms of abuse are rare relative to legitimate use. Stripe sees fraud in roughly one payment in a thousand — and checks more than a thousand characteristics of every payment in under a hundred milliseconds to find it, blocking about 0.1 per cent of legitimate payments by mistake along the way (Stripe). About 6.2 per cent of the web traffic Cloudflare carried in 2025 was mitigated as potentially malicious or blocked by customer-defined rules, 3.3 per cent of it as DDoS attacks or by managed rules (Cloudflare Radar, 2025 Year in Review).

That is the first thing to understand about security: a small fraction of abuse redesigns the experience for everyone. Much of the friction you touch today — passwords, one-time codes, CAPTCHAs, confirmations — exists because of that fraction. We are not complaining. It is proof of how seriously the world takes the protection of systems. We are asking why that seriousness stops at the edge of each system — and so rarely reaches the person standing on the other side of it.

Two waves, one pattern

Cards. When payment cards spread, thieves took the card itself. As chip adoption made counterfeit card fraud much harder — down 87 per cent at chip-enabled US merchants (Visa) — criminals kept adapting. Today a payment can be fully authenticated and still be the result of manipulation. In the United Kingdom in 2025, banks prevented £1.68 billion of unauthorised fraud — and in the same year people lost £576 million by authorising payments themselves, after someone had convinced them to. 248,070 cases, up seven per cent; two thirds began online (UK Finance, 2026).

The payment can be authenticated. The cryptography can work. The person can still lose.

Agents. Now software does not only know. It acts: buys, books, applies, negotiates, moves money. In 2025 pilot tests of a browser agent, hidden instructions on a web page hijacked it 23.6 per cent of the time before mitigations and 11.2 per cent after (Anthropic, 2025); the product has since gained further action-level safeguards. An agent can be talked into acting against you the way a person can. The payment industry is answering with signed mandates (AP2): AP2 lets verifiers cryptographically check that a checkout and a payment match the mandate you signed, shares only the relevant constraints of that mandate, and returns receipts. That is the right answer to its question. Our question begins one level above: does that mandate still fit the rest of your life now?

Each wave shows the same limit: securing the transaction or the agent does not automatically secure the human outcome. Whatever passes through the technical layer lands in a person's life. How long do we keep doing this — securing every new system separately, and leaving the person to carry what is left?

Not every loss looks like fraud

Adults in the United Kingdom spend four and a half hours a day online outside work; 18-to-24-year-olds, six hours twenty minutes; most of it on a smartphone, across 41 apps a month (Ofcom, Online Nation 2025). Time itself is not harm. But in July 2026 the European Commission preliminarily found the addictive design of Instagram and Facebook — infinite scroll, autoplay, push notifications, highly personalised recommendations — in breach of the Digital Services Act, citing risks to the physical and mental wellbeing of users, including minors and vulnerable adults (European Commission, 10 July 2026); TikTok received the same preliminary finding in February. These are preliminary findings, not final decisions. But read what the Commission said, in its preliminary findings on TikTok, about the tools that already exist: the screen-time tools are easy to dismiss and introduce little friction, and the parental controls require additional time and skills from parents. The protection was there. It was left to the person to operate. The point stands: the problem has become large enough that governments are changing the architecture of access itself. Law can set a floor for millions of people. It cannot carry one person's changing limits from one service to the next.

Sometimes what disappears is money. Sometimes it is an hour, a decision, a night's sleep, or a goal you did not choose.

Every system meets you separately

Forty-one apps. Many build their own model of you; each holds its own settings, asks its own permissions, sends its own notifications — and sees its own part. Between them, you are the integration layer.

Remember the bank. It keeps the account on its side. The shop asks for a transaction. It receives a decision — not the account.

Why should the rest of your life work differently? Why should a digital service need your whole life to answer one question?

What is missing

Not another lock. What is still missing is one independent side that travels with the person across systems — a side that knows your limits, your priorities and your direction, and answers on your behalf when a shop, a bank, an employer, a feed or an agent asks for something.

Two questions are already being engineered well. What may you know about me? — credentials, consent, minimal disclosure. What may you do for me? — permissions, scopes, signed mandates. Mediation layers are now emerging around agents too; they protect domains and the interactions between agents. The third question sits above all of this: what remains acceptable for this person, across their whole life, right now? Among the systems we reviewed, we have not found one independent person-side layer that combines, across many executors and over time, whole-life constraints, arbitration between domains, minimal disclosure, protection from reconstruction, the provenance of a goal, protection that continues after an authorised action, and consequences returned into one changing human life. We are testing what happens when the protected domain is one human life across all of it. If you know prior work that already does this, tell us — that is what this page is for.

A payment mandate asks: did you authorise this purchase? The question above it: does this purchase still fit the constraints and the direction of your life today? The mandate can be valid and the purchase can still be wrong for the person's life.

What we are building

Life GPS is a human operating system. Security is its kernel.

Security is not a feature of Life GPS. It is the condition that makes Life GPS possible. A human operating system needs its own security architecture. Not the model's. Not the bank's. Not the platform's. The person's.

The protected thing is not only your data. It is your identity, money, time, attention, relationships, goals, authority and continuity. The threat is not only a hacker. It can be a scammer, an over-permissioned agent, a manipulative interface, a wrong inference, a compromised provider — or the protecting system itself becoming too powerful.

Models are capabilities. Agents are executors. The person has their own side.

One person. One side. Many executors.

The system does not decide what a good life is for you. You define the boundaries; it remembers them, shows conflicts, asks again when the context changes — and the final decision stays yours. The same boundary applies to Life GPS itself. Our own recommendation does not get a free pass.

Security holds the boundary. The Protocol carries your rules into interactions with the outside world. Human Antivirus keeps checking whether even an authorised interaction is still working for you. Recovery keeps your side yours when a device, a model or a provider fails.

We do not need to replace the bank, the shop, the model or the agent. We need each of them to meet the person's side. The better the executors become, the more important an independent side of the person becomes.

Every agent can be right about its task while the whole system is wrong for the person. A financial agent sees money. A work agent sees work. A health service sees health. The person has one life. No executor should optimise one part of your life by silently spending another. That is why the person's side has to see across the whole life — and why no other executor needs to hold the whole of it.

You establish your side once, and it evolves as your life changes: money · time · attention · privacy · what needs your confirmation · what may never be given away · the constraints of your health, your family, your work, your faith, your risk. Then every connected executor — an agent, a shop, a bank, a model — comes to that side and asks what it may do. It receives a decision: allowed · adjust · needs your confirmation · not allowed · not enough context. It gets the decision it needs, not the life that produced it.

An agent should be like an app inside an operating system: powerful, useful, replaceable — but it does not decide its own permissions. On a phone, an app's capabilities are set from outside the app, and stay limited even if the app is compromised (Apple, App Sandbox). We are building that boundary for the person. From blockchain we take trust minimisation, verifiability and resistance to unilateral control — and leave the public ledger of your life behind.

Seven situations, one construction. This is the target architecture, not today's live product — the honest status is below:

Every one of these proves the same thing: an outside system can serve you without owning you.

For businesses, and for the people who build agents

You do not have to know more about a person to serve them better. Ask the person's side what you need for this interaction. Get the answer, the mandate or the confirmation — not the life that produced it.

Concretely, that is not give me the profile. It is four questions and a receipt: can this action proceed under this person's current mandate? what minimum confirmation is required? what minimum disclosure is sufficient? what constraints must this service respect? — and, when it is done, an outcome receipt back to the person's side. That can mean less sensitive data on your servers, less guessing, and potentially fewer wrong actions, returns and disputes. You keep your business; you connect to the person through the protocol.

The API we are designing is access to the person's boundary, not access to the person's database.

Establish it once. Carry it everywhere.

This is not twenty more confirmations. Security engineers have a name for the opposite: secure by design — the complexity of security configuration should not be the customer's problem, and the burden should not fall on the person alone (CISA). You should not have to become a security expert to keep your own life yours.

Nor is your side a rulebook written once and forgotten. Establish it once. Let it evolve continuously. Ask again when the consequence changes. That is why this takes whole-life context, a running check on outcomes and a human antivirus — not a settings screen. The situations above are that target. We describe them as a target, not as a finished product.

Where this stands today

The architecture is designed so that the richest context stays on the person's side and outside systems receive purpose-sized answers instead of the whole person. Some parts of that boundary are already implemented; some are still being closed, and we publish the gaps.

What exists. Between the model of the person and any external AI model there is an outbound gate; the person's memory, the snapshot of their life, the context of their route and their contacts are excluded from it by construction; the model provider is a replaceable component. A boundary for untrusted content and a detector for injected instructions exist. Crisis handling works offline (Life GPS is not a medical, emergency or crisis service — it points to real help). The constraints that govern the system were written before the code that implements them and are published. Scoring a person with a number is forbidden by a law of the system.

What does not exist yet. Not every part of the exchange with an external model is reduced to the same standard yet — closing this gap is open work. Some protective controls are still moving from validation into enforcement. There is no separately verifiable security kernel as a component; parts of it exist. The production recovery layer — coming back to your own life on a new device without a permanently reconstructable identity — is a requirement of the architecture and is not complete. Connections to institutions and agents through the protocol are not switched on. Live calls between people are built and not switched on. There has been no independent audit. Our /security page says we do not claim our systems are secure. That line stays.

The direction is not ours alone. Identity standards already recommend giving a service a derived answer — over 18: yes — instead of the date of birth, wherever the derived answer is enough (NIST SP 800-63C-4). Our next step is to apply that principle not to one credential but to the interactions of a whole life over time. The outside world does not need the whole life that produced the answer.

People, not profiles

Someone has a problem. Someone else has the relevant experience. The match does not require either side to hand over an entire profile — only enough to establish that the need and the capability fit. They talk, help, and return to their lives.

That is a design principle, not a live feature: calls between people are built and open with the first round. We put it here because it shows what the whole architecture is for. Data is not the product. The value is the right interaction with the minimum disclosure.

What the first round is for

Not a roadmap. The first round turns architectural constraints into a system that can be measured under real use: recovery in production, enforcement instead of audit mode, independent cryptographic review, the non-reconstruction layer as exchange with institutions opens, independent red teams and audit.

Some answers only exist at scale: how much context stays on the person's side in practice; how often protection fires wrongly; the minimum authority an agent needs; how fast revocation propagates; how reliably a person's continuity can be restored after loss or compromise; whether separate disclosures can be joined; whether the protection itself starts to push the person. We do not promise the result. We promise the measurement — and to publish it, including where the architecture fails.

Why any of this

Protection is not the point. The point is what it gives back: not explaining yourself to every service; not spending your life in consent screens and settings; agents doing the routine without governing your direction; your money, your time and your attention not spent by every optimiser separately; people and services arriving when they are needed — and the rest of your time staying yours.

We spent decades building layers to protect transactions, devices, accounts, networks and models. The next layer is teaching the digital world how to work with a person without taking the person apart.

When your side belongs to you, technology can finally do more without taking more of your life.

The model can change. The agent can change. The service can change. Your life stays yours.

Do not believe us. Break it: /security. Prior work we have missed, an error, a sector you want to test with us — hello@lifegpsos.com.

Every claim on this page carries a status