Skip to content

Security

Security: how we look after your code, data and keys.

Plain facts about where agents run, how credentials are kept, and what a person still decides. No badges we have not earned.

  • Isolated runs

    In the cloud, each run happens in a fresh, isolated Linux sandbox that is thrown away afterwards. In desktop mode, runs happen on your own Mac, and the built-in file tools used with local models are confined to the job’s working directory.

  • Scoped, encrypted credentials

    Connections use OAuth scopes you grant or keys you supply. In the cloud they are kept in an encrypted vault; on the desktop, in the macOS Keychain. They are injected only when a run needs them, and you can revoke them at any time.

  • Organisation-level access

    Data is scoped to your organisation by row-level security in the database. Team workspaces have Owner, Admin, Member and Viewer roles.

  • A person in the loop

    You set how much agents may do alone. Risky actions become approvals, the first run of any plan needs your yes, and hard daily budgets stop runaway spend.

  • Where it runs

    Our cloud worker runs in London. Product mail is sent through AWS in London (eu-west-2). The database is hosted by Supabase and run sandboxes by E2B. Ask us for the current list of sub-processors.

  • Fully local, if you prefer

    The desktop app can run everything on your Mac against a local database. Paired with a local model through Ollama, nothing leaves the machine.

What we do not claim. Yet.

  • We do not hold SOC 2 or ISO 27001 certification today.
  • We do not train models on your data. Model providers you choose process prompts under their own terms.

Give your product a team that never clocks off.

Start free in the browser, or run it on your Mac with your own Claude Code or Codex plan.