Passwords and Cards
Assistela can securely fill a saved password or payment card in its controlled browser without revealing the real secret to the LLM.
Do not use your main debit card or everyday credit card. For assisted purchases, create a separate virtual card with a strict limit and keep only the amount you are comfortable using for these tasks. A separate wallet or pocket with a small balance is ideal. An unlimited card is a poor fit for assisted web actions.
How secret values are protected
The LLM never receives the real password, card number, expiry date, or CVC. It sees only a safe description and internal placeholder. When Assistela fills a form, the real value is inserted locally in the controlled browser. It is hidden again before page content is sent back to the LLM.
- A password works only on websites you explicitly allow for it.
- You can also restrict a card to specific domains, which is strongly recommended.
- A card without a website restriction always requires approval before filling.
- The saved-item list returns only names and safe placeholders, never the actual secrets.
This protection reduces risk, but it does not make every purchase automatically safe. Always check the website, item, price, currency, delivery, and final confirmation step.
Save a password
Open secure items
Choose Assistela → Settings → Passwords and Cards. Click + below the list and select Add Password.
Name the item
In Name shown to Assistela, enter a description without the secret, for example “Example Store – Peter.”
Enter the password
Put the actual password in the protected Password field. Do not copy it into the name or description.
Add an allowed website
Under Allowed websites, enter only the domain, such as example.com, and click Add. At least one domain is required for passwords. The rule also covers its subdomains.
Save
Click Save. Test sign-in on the correct domain first, without performing another sensitive action.
Save a virtual card
Create a limited card with your bank
First create a virtual card in your banking app, set a low limit, and, if supported, separate its balance from your main account.
Add it in Assistela
Under Settings → Passwords and Cards, click + → Add Card.
Enter a safe description and details
Use a name such as “Virtual card – online purchases.” Enter the card number, expiry as MM/YY, and CVC.
Restrict websites
Add only merchant domains where you actually want the card used. Leaving the list empty is possible, but broadens use and always triggers approval.
Save and monitor it
Save the card, verify bank notifications, and retain a strict daily or monthly limit.
Use a saved item
State the goal and limits, not the secret: “Open example.com and sign me in with the saved password Example Store – Peter. Do not buy anything.” For a card: “Prepare a purchase up to $20 and use Virtual card – online purchases. Stop before final order submission.”
Assistela selects the safe placeholder and inserts the real value only locally into the form on an allowed website. On another domain it refuses to fill a password. A card without a domain restriction waits for your approval.
Rules worth keeping
- Keep a low limit and a small balance on the virtual card.
- Enable instant bank notifications and handle an unusual transaction directly with the bank.
- Do not allow a broad domain when one specific merchant is enough.
- Do not save a card you never want used during assisted work.
- Delete an old password or card from the list, confirming the item name before removal.
- Treat purchase approval as a real review, not a formality.