Capabilities, not badges. Everything below is in the product today — and the last section lists what is not, so you can decide with the whole picture.
Time-based one-time codes with single-use backup codes, available on every plan including Free.
Create keys limited to the specific capabilities they need, see when each was last used, and revoke any one of them without signing your team out.
Four role presets over granular permissions, optional per-agent scoping for a teammate, and billing access reserved to the workspace owner.
Layered rate limiting on sign-in, lockout after repeated failures, and an audit trail of authentication events on your account.
Every read and write is scoped to the workspace that owns it, in the database and in the vector index alike.
All traffic runs over HTTPS with HSTS, and platform credentials for connected channels are stored encrypted.
Your knowledge and conversations exist to answer your customers. We do not sell them, and we do not share them with other customers.
Remove a knowledge source and it is removed from the index your agent searches. Close your account and we cancel billing and purge the workspace.
Set how long conversations are kept; the limit in force is disclosed inside the product next to the data it applies to.
Anonymise or delete an individual customer record — including the arguments captured by any action they triggered — one at a time or in bulk.
Marketing cookies load only after consent, and no analytics event ever carries a customer identifier or a workspace identifier.
Abuse-prevention records store a hashed IP rather than the address itself, and error reports are scrubbed before they leave the server.
Retrieval runs against your own knowledge, and a relevance floor makes the agent decline rather than improvise.
Every action your agent calls is validated and pinned against internal-network addresses, with a per-host circuit breaker and a response size cap.
Each agent carries a monthly budget ceiling and a message-credit meter, so an unexpected traffic spike stops instead of billing you.
High-risk actions require an explicit single-use confirmation before they run, and every run is recorded with its outcome.
Being specific here is part of the point. If any of these is a requirement for you, tell us — it helps us prioritise.
Security questions and responsible disclosure both reach us at the address below. We answer disclosure reports first.