Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Meta’s Muse is built on a specific promise: an agent that acts in your connected accounts should not hold the passwords that open them. Meta’s Secure VM design tries to deliver that by keeping real credentials outside the agent’s runtime and letting a separate control layer, called Sentinel, release them only for authorized outbound requests. On paper, that narrows one serious risk, which is a manipulated agent handing over your secrets. It does not make Muse private from Meta, and two reported privacy concerns that surfaced after launch remain open.

What Muse is and where it runs

Muse is a personal agent. Meta says it can work across the services a user connects, browse the web, fill in forms, and keep working in the background after the app is closed. Meta’s September 2026 launch announcement and Associated Press coverage dated September 8, 2026 both describe the initial rollout as limited to the United States.

Each user gets a dedicated cloud virtual machine, which Meta calls the Secure VM. That machine holds the Muse workspace and data from connected services. Muse is a cloud service reached through software clients, so the security question is about how the service is built and operated, not about any device you own. Nothing in Meta’s launch materials calls for a specific piece of hardware.

How the agent gets access without seeing your credentials

Meta’s technical account, published by Meta AI Research on September 8, 2026, describes the following sequence for any request that needs a credential. These are Meta’s descriptions of its own system, not an independent audit of it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
  1. The runtime holds no real secret. The agent runs in a Linux container separated from the host. When it calls an API that requires authentication, it attaches a surrogate token instead of the real credential.
  2. Sentinel evaluates the request. The outbound request is checked against its destination and request details. Meta also uses data-flow tracking to distinguish processes that have touched user data from those that have not.
  3. Approval, if required. If Sentinel decides the action needs your consent, execution stops until you decide (see the next section).
  4. Substitution at the network boundary. If the request is authorized, Sentinel replaces the surrogate with the real credential at the network boundary. Meta says the main agent never sees the real token.

What “the agent never sees the token” does and does not cover

Meta puts the design claim this way in its technical post: “The agent never sees real tokens, which means any attempt to coerce the agent to reveal the actual secrets via prompt-injection or otherwise is futile.” That is a precise claim about the agent. It covers the runtime that executes instructions, which can be manipulated. It does not cover the company operating the platform, which Meta addresses in its own privacy discussion below.

Existing logins and password managers

Meta has announced planned support for existing logins through 1Password. Launch reporting does not establish that this integration is live, so treat it as a planned capability rather than a current feature.

Approvals, scoped permissions and checkout

When Sentinel decides an action needs your approval, Meta says execution stops and the client presents the requested action directly to you. Your decision goes back to Sentinel, which permits or rejects the operation. Meta says approvals are delivered through the client rather than through the agent’s conversation, so the request you see is not one the agent composes in its own chat.

Meta describes permission grants as scoped along several dimensions:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Connector: which connected service the grant applies to.
  • Destination: where the request is allowed to go.
  • Use case: what the grant is for.
  • Duration: Meta names options such as one-time permission or permission limited to a single task.

Browser work

Meta says Muse uses a Chromium-based browser. A browser sub-agent works from an accessibility-tree snapshot of the page rather than the raw page DOM. Meta says the agent pauses when a person takes over the browser, and also while secure credential storage fills a form, so the agent does not act during either handoff.

Purchases

For purchases, Meta says Muse requests approval at checkout. At launch, Meta named Stripe Link as the payment integration and described single-use card numbers for purchases. The launch announcement said Shop Pay was coming soon, which means it was not available at launch.

Where the protection stops

Meta is direct about the limits of the design. The Secure VM is the system of record for information placed in Muse, but limited data may leave it for inference and telemetry. Meta says operational policies restrict access by its personnel, and adds that those policies do not prevent access when that access is needed to support, secure, or operate Muse.

The table below separates what Meta describes as in place at launch from what it has only planned.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Control Status as Meta describes it What it does not cover
Credential isolation (surrogate tokens, substitution at the network boundary) Described as launch architecture Limits what the agent can reveal. It does not limit what Meta personnel can access in the VM.
Sentinel outbound checks and approvals Described as launch architecture Meta’s own description. The coverage cited here includes no independent audit of the deployed system.
Operational access policies Described as launch architecture Meta says they do not prevent access needed to support, secure, or operate Muse.
Limited data leaving the VM for inference and telemetry Stated by Meta as a standard part of operation Meta describes the amount as limited but does not quantify it.
Confidential VM with cryptographic protections intended to prevent Meta access Planned. In Meta’s technical post it was in testing with a small group. Not described as generally available. Audits and broader availability were still prospective when Meta published.

Reported concerns that remain unresolved

Two reports published after launch raise questions the company’s design description does not answer. Both should be read as reported concerns, not as settled technical findings.

Messages data on a Mac

Tom’s Hardware, in a September 30, 2026 report, summarized journalist Jason Aten’s allegation that Muse on Mac appeared to sync rows from the local Messages database even though the agent had not been granted full-disk access. The report said the mechanism was unclear. As of early October 2026, the coverage does not establish a cause or a fix.

This matters for trust because it concerns data on the user’s own computer, outside the cloud VM that the security design describes.

Information about people who never joined

Tom’s Guide reported in October 2026 that researcher Karan Joshi extracted Muse instructions describing the creation of a page for each person in a user’s life. The report says this could include people who never signed up for Muse. The same report draws a distinction: it did not show a single company-wide profile covering every non-user, and it notes that each customer’s VM is separate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The practical concern is narrower but real. A non-user’s details could enter another person’s agent context whenever that person is discussed.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the bug bounty figures do and do not show

Meta’s bug bounty program, as described in 2026, offers up to $300,000 for valid reports. Meta also cited a maximum of up to $130,000 for successful prompt-injection attempts affecting one user. These are ceilings on awards for valid reports. They are not an incident rate, a safety score, or a count of confirmed attacks, and they cannot be used to estimate how often Muse has been compromised.

Meta’s own framing is modest. In its technical post, Tarek Sheasha, Software Engineer and VP, Meta Superintelligence Labs, wrote: “Like any AI system, Muse will sometimes make mistakes.”

How to evaluate any personal agent’s security claims

Meta describes its approach as “first-of-its-kind,” but that is a marketing claim. A more useful test is to put the same questions to every personal agent and check each answer against the vendor’s technical documentation and independent reporting:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Where do agent execution and memory live?
  2. Can the agent itself read passwords or tokens, or does it only use them through a boundary it cannot inspect?
  3. Who can access stored data, and under what circumstances?
  4. How are outbound actions and prompt injection controlled?
  5. Which actions require approval, and how are approvals scoped?
  6. Have the security claims been independently audited?
  7. What is generally available today, and which integrations are supported?

Answers change as products roll out, so date each one. For Muse, the first two questions are answered mainly by Meta’s own description, and the third and sixth are where the public record is thinnest.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.