Security

Enterprise-level security, from your very first agent

Agents act on your real systems, so the guardrails matter as much as the output. Focus on the work — we handle isolation, encryption, approvals and the audit trail.

Per user

Every integration isolated to the person who connected it

256-bit

AES encryption at rest, TLS in transit

0

Of your data used to train AI models

Isolation model

Shared agents, private access

An agent is a shared recipe, not a shared key. When a colleague runs an agent you built, it uses their Gmail, their CRM and their files — never yours.

  • Credentials are stored per user and encrypted, never exposed to the browser.
  • Database policies enforce ownership on every read and write.
  • Removing someone from the organisation instantly cuts their agents' access.
Per-user connection isolationYouOwn connectionsTeammateOwn connectionsTeammateOwn connectionsAgent runtime
Controls

What protects your data

Security controls are on by default — there is no hardening checklist to complete before you can trust the platform.

Encryption everywhere

Traffic is protected with TLS in transit, and data — including connector credentials — is encrypted at rest. Secrets are stored in a managed vault, never in application code.

Per-user isolated integrations

Every teammate connects their own accounts. An agent shared with the whole organisation still runs each message under the connectors of the person who sent it — nobody borrows anybody's access.

Row-level security by default

Every table that holds your agents, threads, files and credentials is protected by database-level policies scoped to your user and organisation, not just by application checks.

Role-based access control

Admins govern, editors build, viewers run. Sharing is explicit — private, organisation-wide or per-person — and can be revoked at any time.

Approvals for risky actions

Sending an email, writing to a CRM or changing an agent's own settings can require a human approval card that shows exactly what will happen before it happens.

Audit logging

Every run, tool call, approval and settings change is recorded with actor, timestamp and result, so you can reconstruct what an agent did and why.

Managed cloud infrastructure

The platform runs on managed, redundant cloud infrastructure with automated daily database backups and point-in-time recovery.

Least-privilege connectors

Connectors request only the scopes a task needs, and cached tool definitions mean an agent can only call the actions you have added to it.

No training on your data

Your prompts, files and outputs are never used to train models. Model access and spend limits are configurable per workspace.

Our practices

How we run the platform

Operational security

Access to production is limited to a small number of engineers, granted on a need-to-know basis and reviewed regularly. Changes ship through reviewed, automated deployments with the ability to roll back.

Network security

Services sit behind managed firewalls and DDoS-protected edge infrastructure. Network rules and public surfaces are reviewed as the architecture changes, and public API routes verify the caller before doing any work.

Backup & recovery

Databases are backed up automatically every day and replicated across availability zones so a hardware failure does not become a data loss event. Restores are tested as part of infrastructure changes.

Privacy & data rights

We process personal data in line with GDPR principles: lawful basis, minimisation and transparency. You can export or delete your workspace data, and retention windows are configurable.

Vulnerability management

Dependencies are scanned continuously and the platform is checked by an automated security scanner covering database policies, authentication and exposed data before every release.

Incident response

Security events are triaged against a documented runbook, with affected customers notified without undue delay and a written follow-up once the root cause is understood.

In your hands

Controls you own

Governance lives in the product, not in a support ticket.

Decide who can see, edit and run every agent.
Require approval before agents take real-world actions.
Disconnect any integration instantly, from the agent sidebar.
Review the full history of what each agent did on your behalf.
Restrict which AI models a workspace may use.
Export or delete your workspace data whenever you choose.

Questions from your security team?

We are happy to walk through our architecture, complete your vendor questionnaire or sign a DPA before you roll out agents.