Trust & truth

What will it say to
my customers?

If you are going to put a talking character on your website, the question that actually matters is not how it looks. It is what it will say, and what it will do with what your visitors tell it. This page answers that as plainly as we can — including the parts that are not finished.

Where answers come from

NetShow Alive is the face. It is not the brain.

The thinking is done by a model you connect, and that shapes everything on this page. There are three routes an answer can travel, with very different properties.

ROUTE ONE

The offline local agent

Rule-based, deterministic, no keys, no connections. Its own header states the rule: “no network, no keys, no connects — the whole agent is local rules + timers.”

We verified that structurally rather than believing the comment: the entire 167-line file contains zero fetch, zero XMLHttpRequest and zero WebSocket calls. It cannot phone home, because there is no code in it that could.

ROUTE TWO

Your own model, your own keys

The intended production shape: “Any model, any voice, no keys here.” Your conversations “touch your infrastructure only.” The answers are exactly as good, and as truthful, as the model and instructions you bring.

ROUTE THREE

A managed live session

Where NetShow runs the conversation, the provider credential is resolved server-side and never reaches the visitor’s browser. These sessions are “processed to provide the service, not sold.”

THE ONE QUALIFICATION ON “NO KEYS HERE”

That phrase is true of routes one and two, and it is always true that a provider key never reaches a visitor’s browser. It does not mean no key is ever used on your behalf: where a business has no key of its own on file, the relay resolves one server-side — “business vault key wins, platform key under demo mode.” Worth knowing which of those you are on, particularly during a demo.

The honest gap

Read this one.

Here is the thing a sales page would not tell you. Today, a NetShow Alive agent’s answers are generated, not quoted from your documents. The capability that would change that — an extractive answer engine, where a reply is lifted from your source material with a citation instead of composed by a model — is built and proven, but not switched on.

BOTH SIDES, WITH THEIR SOURCES

The state as of today. The engine was designed, built and evaluated on 2026-08-10 as a proposal: “BUILT + VERIFIED — SERVE-READY 0 (build-only lane; everything gated)”, with the work sitting on an unmerged branch — “NOT pushed, NOT merged; diffs are the product.” It is off by default. Until it lands and is switched on, nothing in your live agent changes.

What it does when it runs. In evaluation across 30 real business questions it produced zero wrong-fact extractions across 79 judged extractions. Against a seeded document set it answered 20 of 30 questions extractively at 95% precision. On today’s live configuration it extracts 0 of 30, and every reply falls back to one that is marked as generative.

A second reason it would change nothing yet, even switched on. The document library it would quote from is empty: the only publish-eligible folder “holds exactly one file (its README, 2,044 bytes)”. Turning it on is one step; giving it your documents to quote is another.

Your agent’s truthfulness is your model’s truthfulness, shaped by the instructions and guardrails you give it.

If someone demonstrates this product and calls it “zero-hallucination,” they are describing a capability that is built, evaluated, and not yet turned on — not the answers your visitors are getting right now. We would rather you deploy with an accurate picture than discover this from a customer.

What it will not do

Controls that are enforced in code, not requested in a prompt.

  • Rules are checked on every single turn. You can write guardrails — instructions it must obey and topics it must refuse — and the pipeline that enforces them runs before and after every runtime turn. It is on by default, not an extra to switch on.
  • A violating answer is stopped mid-sentence. Output-type rules cut off the reply for that turn rather than letting it finish and apologising afterwards.
  • It can be made to ask permission before it acts. An agent’s attempt to use a tool can be held for a person to approve, reject or snooze — which is why the character has a “Waiting for Approval — Asks before acting” posture.
  • It shows uncertainty instead of bluffing. “Uncertain — Shrugs and flags low confidence” is a first-class state, as is “Error — Owns the failure, visibly.”
  • Nothing starts spending on its own. A billed conversation can only begin from a genuine human click, checked in code, with no automatic mode available at all.
  • An agent record carries no secrets. We checked all fourteen exported records: every one reads secretsEmbedded: false. Published character files are face data and greetings only — explicitly “not a credential.”
THE MOST IMPORTANT CAVEAT ON THIS PAGE

Treat topic guardrails as a steer, not a wall. The separate topical guardrail, which judges whether a visitor’s request is on-topic, fails open by design: its own documentation states “On ANY failure: returns ‘allowed’ (safe fallback — never hard-block on error).” If it errors, or is unconfigured, the request proceeds. It also works by asking a model — it posts the visitor’s request to an external provider to make the judgement.

Two consequences to design around: do not rely on a topic guardrail as a security control for anything that would be harmful if it let a request through, and be aware that topic-checking sends the visitor’s question to an outside provider.

What leaves the browser

And what does not.

What happens
The character’s animation“Runs locally in the visitor’s browser. Animation never round-trips a server, and no video of the character is streamed to or from NetShow.”
Conversations“Flow through the model and voice stack you connect. Bring-your-own means they touch your infrastructure only; managed sessions are processed to provide the service, not sold.”
Uploaded photos“Processed to build a stylized profile; source images are not stored by default and metadata is stripped where practical. You choose local-only or server processing at upload time.”
Likeness profiles“Stored in your workspace as stylized feature parameters (not photos), with visible delete and reset controls.”
Microphone audio“Only after an explicit button press, only while indicated as active.”
Analytics“Event names with coarse properties (e.g. which style was picked). Blocklisted: photos, transcripts, message content, audio.”
TWO OF THOSE WE CHECKED OURSELVES RATHER THAN REPRINTING

The Create studio genuinely cannot upload your image. Searching the whole page for network calls returns nothing — no fetch, no XMLHttpRequest, no FormData. The local-only promise shown at upload time is structurally true on that page.

But the same page does send anonymous usage events. Your image is not sent. Which starter you clicked is. The analytics blocklist above is what keeps those two facts compatible — photos, transcripts, message content and audio are excluded by policy.

Your microphone is off until you start a call, and the browser asks permission then and only then. You never have to speak at all — typing works, and captions are always on.

When it does not know

Three ways it tells you instead of guessing.

  • The character has a posture for it and uses it — Uncertain, visibly.
  • The offline agent says it is rule-based and suggests connecting a larger model. To be precise: it answers from three varied fallback lines picked at random, two of which name the limit directly and one of which simply echoes the question back — an honest tendency rather than a guarantee on every turn.
  • When something breaks in an embedded agent, the visitor gets a short honest card naming what went wrong — never a blank box, never a stand-in face pretending to be yours. “Silence is never an acceptable failure.”
What we will not claim

Four things you will not hear from us.

  • Not that answers are grounded in your documents today — see the honest gap above.
  • Not a price from the wider NetShow platform catalogue, because those prices were never reconciled against the payment system and the configuration says so itself. The published NetShow Alive plans are a different, live surface and we quote those.
  • Not that the seeded business tenants are live to the public — all fourteen exported records read deployment.status: draft, and eleven of the thirteen are merely queued for the shelf.
  • Not that full-body 3D is available — the studio cannot make one and the embed does not carry one.
IF WE CONTRADICT OURSELVES, THAT IS THE BUG

If you find a claim on any NetShow Alive page that this document contradicts, the contradiction is the bug. Tell us: ai@netshow.ai.

Questions we did not answer?

Ask them. We would rather write down another inconvenient fact than have you find it later.