Security & Trust

Security, built in from day one.

We're an early-stage product — here's exactly what's shipped today, and what's still on the roadmap.

Encrypted in transit and at rest

TLS everywhere in transit. Provider credentials are encrypted at rest, per connection, and are never returned in plain text by our API.

Live credential validation

Every connected provider key is validated on save and can be re-tested at any time, so you always know if a credential is actually working.

Role-based access control

Owner, Admin, Member, and Viewer roles map to exactly what each teammate can see and change in a workspace.

Audit trail

Every sensitive action — invites, role changes, credential rotation — is logged.

Least data by default

We store usage metadata — tokens, cost, model, timestamps. We never collect prompt or completion content.

One account system

A single, unified authentication system backs both the marketing site and the dashboard — no parallel account stores.

On the roadmap

These are coming soon — we'd rather tell you what's next than claim it's already here.

Single sign-on (SSO / SAML)Coming soon
SCIM provisioningComing soon
Bring your own key management (KMS)Coming soon
Formal compliance certifications (SOC 2, etc.)Coming soon

Questions about security?

Reach out and we'll walk you through exactly how your data is handled.

Contact us