SECURITY & TRUST

Security, written out.

Our competitor's headline is "100% private," and it is true. Ours is a hosted platform, so the honest answer is longer than one line. Here is precisely what we hold, what we never see, and what stands between a stranger's plugin and your servers.

Your model keysStored encrypted with a per-account key, decrypted in memory only to make a provider call. Never logged, never included in a transcript, never sent to a plugin. Inference is billed by your provider to your account — we are not in that path.
Untrusted code is cagedThird-party plugins execute in an isolated V8 environment reached over gRPC. No filesystem, no network beyond declared endpoints, no access to secrets, hosts or other tenants. First-party capabilities run native. The tier is on the card before you install.
Nothing implicitAn agent can reach a host only if the host is verified for your account and allow-listed for that agent. Same for peer agents, commands and skills. A new agent starts with nothing.
WHAT WE HOLD

And what we do not.

Vagueness here reads as evasion, so this is specific.

WE STORE
Session transcripts, including tool arguments and results.Files in agent and account workspaces.Agent configuration — souls, instructions, permissions.Host records and SSH credentials, encrypted at rest.Spend and usage records per session, agent and model.
WE DO NOT
Train on your transcripts, files or configuration. Ever, on any plan.Resell inference or sit between you and your provider's billing.Share data across tenants — isolation is enforced at the query layer, not by convention.Log decrypted secrets, keys or credentials.Give plugins access to anything they did not declare.
SPECIFICS

The parts people ask about.

SSH host verificationA host is registered per account and proves control before any agent may use it. Verification records the fingerprint; a changed fingerprint suspends the host until you re-verify. Hosts can connect directly or over a reverse tunnel, so you can add a server without opening a port.
Per-agent permissionsHosts, peer agents, commands and skills are allow-listed individually. Denials are explicit and logged. A subagent inherits only what its parent grants it, never more.
Secret handlingEncrypted at rest with per-account keys, decrypted in memory for the duration of a call. Redacted from transcripts, exports and support access. Rotating a key does not require touching agents.
Tenant isolationEvery record is scoped to an account at the data layer. Sandboxed plugin instances are per-session and torn down after. Workspaces are quota'd and never shared across accounts.
Sandbox boundaryIsolated V8, no ambient filesystem or network, gRPC calls into a declared API surface only, wall-clock and memory limits per invocation. A misbehaving plugin fails its own call, not your mission.
Audit and accessTeam accounts get an audit log of agent runs, permission changes and installs. Support access to an account requires an explicit, time-boxed grant from an owner.
ComplianceSOC 2 Type II in progress, report expected Q4. DPA available on team plans. Sub-processors listed and versioned in the legal pages.

Crews of expert agents that finish the work.

Create an account, add your model key, and write your first agent's soul. The rest of the crew can arrive in one click.