Security & trust
Agents with access, under control.
Agents touch your inbox, your spreadsheets and your customers. This is what keeps that work isolated, supervised and on the record, described as it works today.
Workspace isolation
- Every workspace is isolated by Postgres row-level security. Agents, runs, events, keys and approvals are readable only by members of that workspace.
- The application also scopes every query to the active workspace, so isolation never rests on a single check.
- Members see the folders and teams they have been granted, plus the agents they created.
- Access to production data is restricted to authorised personnel. When you report an issue, our team may read the relevant run logs to diagnose it.
Roles
- Owner: everything, and the only role that can delete the workspace.
- Admin: workspace settings, billing, members and AI provider keys, plus everything a member can do.
- Member: builds and runs agents in the folders they are granted, sets up schedules and custom tools, and approves or rejects gated tool calls.
- An invite makes someone an admin or a member. Nobody is invited in as an owner.
Credentials
- API keys are stored only as a SHA-256 hash and shown once, when they are created. A lost key can be revoked and replaced, never shown again.
- Custom tool secrets, MCP server secrets, OAuth tokens and client secrets for custom tools, and AI provider keys are encrypted with AES-256-GCM before they are stored. They are decrypted only on the server, to call the service they belong to, and never shown back in the dashboard.
- Only owners and admins can add or change AI provider keys.
Human approval and safe testing
- Any tool can require approval. A gated call pauses the run until a person approves or rejects it. An approval nobody answers expires after 24 hours, and the run ends without taking the action.
- Test runs and evals stub out write actions: a tool that would send or write returns a description of what it would have done, and nothing leaves the system. Read-only tools run for real, so the test stays realistic.
Audit log
Enterprise- An append-only log of administrative actions, visible to owners and admins. Nobody in the workspace, admins included, can edit or delete an entry.
- It records API keys created and revoked, AI provider keys saved and removed, members invited, joined, removed and changed role, budgets created, changed and deleted, agents deleted, changes to an agent's tools, approval gates and status, and workspace settings changes.
- Values that look like secrets are redacted before an entry is written.
Network egress
- The built-in web tools, custom HTTP tools, OAuth token endpoints and MCP servers refuse URLs that point at private IP ranges, localhost, link-local addresses or cloud metadata endpoints.
- For the built-in web tools, custom HTTP tools, OAuth token endpoints and MCP servers, every redirect is checked again before it is followed.
- Custom model endpoints must use HTTPS and pass the same check.
Your data
- Data is encrypted in transit (TLS 1.2+) and at rest.
- AgentOS does not use your agent content, system prompts or run data to train AI models. When an agent calls a model, the request goes to that model provider and is handled under the provider's own terms. See the privacy policy.
- The services we rely on, what each one does and where, are listed as sub-processors in the privacy policy.
- When you delete a workspace, its data is permanently deleted within 30 days.
Self-hosting
Enterprise- AgentOS can run on your own infrastructure. The whole stack (database, auth, realtime, storage, the app and its scheduler) ships as a Docker Compose deployment, or the app can run on Vercel against a data layer you host.
- Agents reach models inside your network only through an allowlist your operator sets. Custom tools stay blocked from private addresses either way.
SDK safeguards
- From version 0.4.1, the TypeScript SDK keeps your API key out of logs: it no longer appears when a run, task or span is serialised or inspected.
- It does not follow redirects, and it warns when a base URL other than localhost uses plain HTTP.
Reporting a vulnerability
- Email bernabranco@agentos-ai.dev. We aim to acknowledge reports within 48 hours.
Questionnaires and reviews
- We complete security questionnaires and answer reviews directly. Ask us about SSO, data location or anything this page doesn't cover. Contact us.