Security

Powerful AI, on a short leash

Every agent works inside guardrails you can see and control — rules, approvals and isolation are enforced by the engine, not left to the model.

Injection barrier

After an agent reads untrusted content, anything it then tries to do is held for your review — a prompt hidden in a page or email can’t make it act.

Human approvals

Set thresholds that pause a tool-action for sign-off before it runs; nothing over the line happens without a person saying yes.

Graduated autonomy

Agents earn independence step by step — supervised → assisted → autonomous — and raising the level always needs your approval.

Egress guard

Outbound requests are filtered against a strict allow-list, so an agent can’t be steered into reaching internal or unexpected addresses.

Tenant isolation

Every workspace is walled off under a default-deny policy — your data never crosses into another tenant.

Your keys, your data

Bring your own model key and connect your own credentials; secrets are encrypted at rest and never shown to the model.

Even a fully autonomous agent still hits the security floor — the guardrails apply no matter how much freedom you grant.

Honest about where we are

Certifications are on the roadmap

We’re in free beta. Formal certifications such as SOC 2 are on our roadmap, not yet in place — we’d rather tell you that plainly than imply otherwise. The controls above are shipped and in use today. See our full standards posture on the Trust & compliance page.

Have a security question or want to report something? Email [email protected].

Put agents to work — under your control

Start with one agent and the guardrails on from day one.