Before Tab can pay for a purchase, the company says, the user must approve the exact merchant, amount, and recipient. Its text-message AI assistant promises to book travel, call businesses, and prepare purchases, pairing delegated work with explicit transaction controls.
Tab’s product page labels the assistant a private beta and directs prospective users to a phone-number waitlist. The launch introduces a service seeking users’ trust; it does not establish that a broadly available assistant can reliably complete everyday tasks.
According to TechCrunch’s launch report, Tab announced its emergence from stealth on October 6, 2026. Co-founder Ammar Amdani described an assistant reachable through iMessage or WhatsApp. Behind that familiar conversation are questions about which actions Tab can take, where its authority stops, and which claims remain untested.
Messages Are the Interface, Not the Execution Environment
A request in a message thread starts Tab’s proposed workflow. Examples include finding and booking a flight, calling a hotel to move a reservation, converting a PDF into a spreadsheet, and ordering a replacement part.
Users can send text, photos, screenshots, PDFs, and video, according to the company. Tab asks clarifying questions, provides short progress updates, and returns results to the same conversation. For longer jobs, it says work continues after the user leaves the thread, with context retained for later follow-up.

The assistant also has its own computer and browser, Tab says. These tools let it open websites, create files, and use accounts the user connects. Messaging handles requests and responses; execution happens elsewhere.
Removing a separate app may make delegation easier, but navigating websites, interpreting documents, and managing account permissions remain complex. A short message can initiate a task whose consequences extend well beyond the conversation.
Phone calls are part of the pitch too. Tab says it can contact hotels, medical offices, restaurants, and vendors, wait on hold, ask questions, and report back. The launch sources do not establish how reliably it handles those conversations or recovers when a business cannot fulfill the request.
Joining the Waitlist Does Not Establish Access
The public signup flow asks for a name and mobile number, followed by a required text to complete enrollment. Tab’s site does not disclose general pricing, a supported-country list, or how quickly waitlisted users will receive access.
An international country-code selector does not prove that the assistant operates in every listed country. Collecting a number and supporting calls, messaging, account connections, and payments in that location are separate questions.
Even beta access does not necessarily include every advertised capability. Tab’s security documentation identifies wallet and automated checkout as limited-beta features, enabled only when the required private services are healthy and available for that user.
Prospective users face two availability questions: whether they can enter the private beta, and which actions their account can perform once admitted. The published material provides no rollout schedule that resolves either one.
Payment Approval Is Bound to a Specific Transaction
Tab’s most concrete safety claim concerns spending. Its product page says users see what is being purchased, the total, and who receives payment before approving it. According to the company, nothing is paid until that approval.
The security documentation describes the mechanism in more detail. Before an eligible checkout receives card data, Tab creates a short-lived transaction authorization tied to the user, task, merchant, cart, recipient, currency, exact total, saved card, browser session, payment-frame origins, and deadline. A separate checkout boundary rechecks those terms before filling payment fields.
This is intended to prevent approval from becoming a general license to spend. Authorization for one purchase should not silently apply to a different merchant, changed total, or substituted recipient. Whether Tab consistently enforces those checks remains unverified in the cited reporting.
The documentation also addresses uncertainty after submission. A timeout does not necessarily mean a payment failed, and retrying could create a second charge.
Tab says a processing state, changed target, timeout, or unknown outcome blocks an automatic retry. It treats a purchase as complete only after the merchant displays a matching confirmation on a distinct page from the same website origin. Bank challenges, passkeys, one-time codes, and 3-D Secure checks may require the user to take over.
These specific design commitments do not establish that every external action receives identical approval. The documentation separately describes default-deny controls for unknown tools and connected-app write actions. Those actions must be explicitly enabled; a broad wildcard permission does not cover them.
The Planning AI Receives References, Not Raw Secrets
Tab says passwords, card numbers, security codes, access tokens, and browser authority stay outside Messages and the planning AI’s ordinary working context.
For website credentials, the documented process gives the AI an opaque credential identifier, an account label, and a permitted website origin. The password is encrypted before storage and decrypted only inside a separate credential-filling boundary after the active user and website origin match.
Connected accounts follow a similar separation. Provider credentials and raw access tokens remain in server-side or provider-managed systems. The AI works through structured, scoped actions and receives filtered results without the underlying secrets.
Card enrollment uses another private flow. Tab says its single-purpose enrollment link expires after 10 minutes. Full card and billing details go to an isolated vault endpoint, bypassing the message thread. The core application is designed to receive an opaque card reference and limited display metadata, including the brand and last four digits.
Under this architecture, an AI can request an authorized action without needing the secret that enables it. Keeping secrets out of ordinary model context reduces the places where they could be exposed.
Users still have to trust Tab’s infrastructure. Credential storage, authorization checks, checkout services, and browser controls must work correctly. The assistant could also plan the wrong purchase or misunderstand an instruction. Secret isolation and task accuracy address different risks.
Credential Isolation Does Not Make Task Data Private by Default
Tab’s privacy policy, effective September 2, 2026, describes substantial processing beyond passwords and payment details. It includes messages and attachments, task outputs, browser activity, connected-account results, and purchase information such as shipping details, approvals, and receipts.
When Tab places a call, it processes the destination, instructions, status, and result. Calls may include recordings or transcripts when the feature is configured for them and applicable notice or consent requirements are addressed. Users should not assume every call is recorded, or that none are.
Service-provider categories listed in the policy may handle information to operate the product, including messaging, calling, browser automation, file processing, and private vault or payment services. Separating credentials from the planning AI does not keep all task information within one system.
Amdani told TechCrunch that user data is never used to train AI. The launch reporting does not independently verify that company assurance.
Tab’s practical guidance is narrower and useful: do not send passwords, full card numbers, or security codes in Messages; use the private flows instead. Users can also ask Tab to disconnect accounts or revoke access through the connected provider.
Competition Will Turn on Completed Tasks, Not Promises
TechCrunch places Tab alongside personal assistants such as Instinct and Meta’s Muse. The cited sources establish its competitive context in the AI industry without providing a controlled comparison of completion rates, prices, or permission systems. They do not support declaring Tab more capable or safer than those rivals.
TechCrunch also says Tab emerged from stealth at a $300 million valuation, while the company declined to disclose exact funding details. That figure signals investor expectations, not demonstrated reliability.
Tab’s launch offers unusually specific claims to test: whether a changed checkout total invalidates approval, whether an uncertain payment stops rather than retries, whether credentials remain outside the planning context, and whether calls and bookings finish with accurate confirmations.
Neither the launch material nor the TechCrunch report provides independent completion-rate testing, comparative performance evaluation, or security audit results. Tab remains a private-beta proposition with a documented control model. Its strongest competitive evidence will be successful task completion and demonstrated enforcement of those limits, especially when a website, business, or payment flow behaves unpredictably.
Sources
- Tab’s product pagetab.bot
- TechCrunch’s launch reporttechcrunch.com
- security documentationtab.bot
- privacy policytab.bot





