Security is not
a feature.
It's the architecture.
Everything we protect. Everything we don't. Verified independently. No vague promises — only verifiable facts.
Things we have never done.
And structurally cannot do.
We have never accessed a customer's encrypted vault contents.
We have never decrypted customer vault data — even on our own servers.
We have never shared credential data with any third party.
We have never installed monitoring or surveillance software at a third party's request.
We have never modified agent behavior or policies without customer consent.
We have never retained customer data after account deletion beyond the stated period.
This list is updated with every transparency report. Last reviewed: June 2025.
Core security principles. Four pillars.
Every claim is verifiable. Every section is public.
Encryption Guarantees
AES-256-GCM encryption for all vault contents. Data is encrypted at rest and in transit.
Bring Your Own Key (BYOK)
Maintain ultimate control. Use your own AWS KMS or Google Cloud KMS keys to encrypt your vault. Revoke access instantly.
Complete Auditability
Every token exchange, proxy request, and policy evaluation is recorded in an immutable, cryptographically-verifiable log.
Human Oversight
Zero rogue actions. Require explicit human approval via Slack or push notification for high-risk endpoints.