TheLibrarian.io
13 fields evidenced · 42 with no public information. Every value below links to the document it came from and the date we checked it.
Also appears in
Trust gap
How this is scoredAre scope, spend, and authority enforced while the agent runs?
The /security page states it requests only the minimum permissions needed to provide its features - a scope limit at the authorisation boundary, enforced in practice by Google's OAuth scopes. Not 2 or 3: no runtime enforcement of spend or authority, and no customer-configurable limit, is published.
Counts Permission scopes, each cited below.
How this gap gets closed →Is there a tamper-evident record of what it actually did?
No public evidence found of any record of the agent's own actions. The /security page's "strict internal controls and audit logs to monitor access" describes vendor-internal monitoring of staff access to customer data, not a reviewable record of what the agent did; the audit_trail field resting on that span was downgraded in this audit for the same reason.
Our automated recount on Oct 6, 2026 counted enough evidenced fields for 1/3. It never reads what those fields say, so it does not overturn the score above, judged on Oct 8, 2026 — but where the two disagree it is a reason to read this dimension again. Why there are two scores
Rests on Audit trail and Tamper-evident log, recorded as undisclosed and cited below. For a 0 that absence is the finding. What a score rests on
How this gap gets closed →Are compliance obligations attached per engagement?
Completed Google's Cloud Application Security Assessment (CASA), a third-party audit required for applications accessing restricted Google API scopes - a real published assurance artifact. Against that, the page states SOC 2 compliance is a work in progress with certification only anticipated in 2026, so no certification is held. Scored 1.
Counts Compliance certifications, each cited below.
How this gap gets closed →Does payment depend on a verified result?
No public evidence found. No pricing appears on either captured page, and outcome_based_pricing, settlement_mechanism, pricing_model and price_point are all no_public_information. Unlike an evidenced zero, nothing here establishes the payment basis in either direction.
Rests on Settlement mechanism and Outcome-based pricing, recorded as undisclosed and cited below. For a 0 that absence is the finding. What a score rests on
How this gap gets closed →Can the deployment be insured, and is the customer indemnified?
No public evidence found. insurance_available, insurance_carriers, coverage_limits and indemnification are all no_public_information against the captured pages.
Rests on Insurance available, Insurance carriers, Coverage limits and Indemnification, recorded as undisclosed and cited below. For a 0 that absence is the finding. What a score rests on
How this gap gets closed →Assurance
- Insurance available
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Insurance carriers
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Coverage limits
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Indemnification
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Liability cap
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Audit trail
- no public informationthelibrarian.io · checked Sep 24, 2026 · source did not state this
- Tamper-evident log
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Explainability
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Runtime governance
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Permission scopes
- States it requests only the minimum permissions needed to provide its features.
“We request only the minimum permissions needed to provide our features.”
thelibrarian.io · checked Aug 20, 2026 - Compliance certifications
- No certification held: the page states SOC 2 compliance is in progress, with certification anticipated in 2026.
“SOC2 compliance is a work in progress, with certification anticipated in 2026”
thelibrarian.io · checked Aug 1, 2026 - Regulatory alignment
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Outcome-based pricing
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Settlement mechanism
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Dispute process
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- SLA terms
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Evaluation coverage
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
Agency
- Autonomy level
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Human oversight
- Deletions require explicit user approval.
“No Deletions Without Consent”
thelibrarian.io · checked Sep 24, 2026 - Goal complexity
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Action space
- Reads Gmail messages, Calendar events and Drive files to power the features the user enables.
“such as Gmail messages, Calendar events, and Drive files, to power the features you use”
thelibrarian.io · checked Sep 24, 2026 - Operating environment
- Acts inside the user's existing tools; the cited span names Gmail and Notion.
“Gmail, Notion, and your other tools”
thelibrarian.io · checked Sep 24, 2026 - Initiative
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
Safety
- Safety evaluations
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Red teaming
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Safety policy
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Usage restrictions
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Model or system card
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Incident reporting
- Publishes a vulnerability/security-issue reporting channel via email, with a stated commitment to investigate reports promptly.
“please contact us via email . We take all reports seriously and investigate promptly.”
thelibrarian.io · checked Aug 20, 2026 - Third-party evaluations
- Completed Google's Cloud Application Security Assessment (CASA), a third-party security audit required for apps accessing restricted Google API scopes.
“The Librarian completed Google's Cloud Application Security Assessment (CASA), a third-party security audit required for applications accessing restricted Google API scopes.”
thelibrarian.io · checked Aug 20, 2026 - Data handling
- All user data encrypted in transit and at rest, AES-256 for disk storage; indexing respects original file permissions and access is restricted by access controls.
“Unbreakable Data Encryption All user data is encrypted in transit and at rest, using AES-256 encryption for disk storage—the industry standard of data protection. Privacy at Every Step The Librarian protects your interactions with strict access controls and indexing that respects original file permissions.”
thelibrarian.io · checked Aug 1, 2026
Practicality
- Pricing model
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Price point
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Availability
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Deployment options
- Mobile apps for iOS and Android.
“iOS and Android apps”
thelibrarian.io · checked Aug 1, 2026 - Integrations
- Names MoxiWorks, MLS, Zillow, Redfin, BoldTrail CRM, Google Calendar, Gmail, WhatsApp, Notion, Slack, SMS and LinkedIn.
“MoxiWorks Manage contacts, sync tasks, and streamline follow-ups. MLS Access listing data, check status, and retrieve comps. Zillow Pull listing insights, Zestimate context, and market snapshots. Redfin Track listings, sale comps, and local price trends faster. BoldTrail CRM Sync contacts, leads, and follow-up workflows in one place. Google Calendar Schedule showings and sync appointments. Gmail Draft emails and automate follow-ups. WhatsApp Respond to clients instantly with updates. Notion Organize deals and track pipeline. Slack Coordinate with your team in real-time. SMS Send timely text messages to clients. LinkedIn Share posts and grow your network.”
thelibrarian.io · checked Aug 1, 2026 - Supported regions
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Support model
- Support offered over WhatsApp messaging.
“Whatsapp Support Message us on WhatsApp”
thelibrarian.io · checked Aug 1, 2026
Foundation models
- Base models
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Model provider
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Model swappable
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Open weights
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Fine-tuning
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Context window
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
Ecosystem
- Protocols supported
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Tool use
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Multi-agent
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- API access
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Open source
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Marketplace presence
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
Impact
- User base
- Unquantified vendor claim of adoption by leading real estate agents.
“Trusted by leading real estate agents”
thelibrarian.io · checked Aug 1, 2026 - Deployment scale
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Target sectors
- Sold into real estate.
“Real Estate”
thelibrarian.io · checked Aug 1, 2026 - High-risk domains
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
- Documented incidents
- no public informationthelibrarian.io · checked Aug 1, 2026 · source did not state this
In the wire
Reporting backed by the same source documents as TheLibrarian.io’s own evidenced fields.
Frequently asked
- What is TheLibrarian.io?
- Does: Reads Gmail messages, Calendar events and Drive files to power the features the user enables.
- How much does AI Dispatch know about TheLibrarian.io, and how is it verified?
- 13 fields are evidenced, each with a cited source document and retrieval date. 42 are recorded as no public information — meaning the cited source does not state it, not a gap AI Dispatch has left unchecked.
- Does TheLibrarian.io have a published trust gap?
- Yes — 5 of 5 scored dimensions (Runtime governance, Audit trail, Compliance, Outcome settlement, Insurance & indemnity) is rated 0 or 1 out of 3 by a human reviewer against AI Dispatch's published trust-gap rubric.
- What are the alternatives to TheLibrarian.io?
- 39 other published productivity entries are in the same category as TheLibrarian.io in the AI Dispatch index, each with its own cited fields.