Security & data
What is running today, and what is not
This page puts up no certification badges, because we have none. Below are the mechanisms that genuinely run in this product, followed by an open list of the things we have not built. We think that second list serves you better than an empty badge row.
One company’s data stays enclosed
Every read filters by workspace first. A request from outside the membership is not answered “forbidden” but “not found” — so even the existence of the data does not leak.
An agent has no rights of its own
An agent’s permissions are always judged against the person who set it going. It cannot see anything that person may not see.
Outbound actions need a yes
Sending, posting or paying always stops at the approval queue. That gate is enforced by the server, not requested in a text instruction.
Anything that matters leaves a trail
Sensitive actions are recorded with actor, time and target. Every piece of agent work has a step-by-step transcript.
Roles
Who may do what
Four roles, with no elaborate permission matrix. If you need finer control, that is among the things we have not built — and it is on the list below.
- Owner
- Manages the plan and billing, changes anybody’s role, and is the only one who can delete the workspace.
- Admin
- Invites and removes members, creates divisions and agents, decides approvals, reads the audit trail.
- Member
- Does the day-to-day work, creates personal agents, and decides approvals for agents acting on their own behalf.
- Agent
- Not a human role. Its permissions are inherited from whoever triggered it, then narrowed again by the tool allowlist its owner set.
Agent guardrails
Six limits that make an agent safe to assign
Every one of these is enforced server-side. An agent cannot talk itself past them, and an instruction telling it to break one will not work.
A tool allowlist
There are 19 tools an agent can use. You choose which ones each agent may touch — except the tool that closes a run, which is always on so every piece of work ends on the record. The rest simply do not exist for that agent.
A spending cap
Each agent has a rupiah cap per month. Once it is reached, tasks are held — not quietly run anyway.
Optional web access
An agent cannot reach the internet unless you switch it on for that agent.
Channel scope
An agent reads only the channels you name. Private channels and direct messages stay closed unless access is granted explicitly.
Attempt and time limits
A failed run retries at most once, then stops with the reason recorded. No agent spins forever.
No unbounded agent-to-agent calls
Agents do not reply to agents in chat, and delegation between agents is bounded so no chain runs away.
The open ledger
Running, and not running
A crossed row does not mean “coming soon”. It means it does not exist, and if you need it now you should know that before you sign up.
| Item | Status | Note |
|---|---|---|
| Data isolation between companies | Running | Tested automatically every release: 133 cross-tenant leak checks, all of which must pass before code ships. |
| Sign-in with Google or an email code | Running | We store no passwords in production. |
| Audit trail of sensitive actions | Running | Role changes, deletions, approval decisions and agent permission changes are recorded with actor and time. |
| A full transcript of every agent run | Running | Tools used, data read, and the rupiah cost — open to anyone entitled to see that issue. |
| Encryption in transit (HTTPS) | Running | All traffic uses TLS. |
| Delete a workspace and everything in it | Running | The owner can do it themselves in Settings; the data goes with it rather than being hidden. |
| SSO / SAML / LDAP | Not yet | Not built. If this is a hard requirement for your organisation, this product does not fit yet. |
| SOC 2 / ISO 27001 certification | Not yet | We have neither, and we will not display a badge before a real audit. |
| Data stored inside Indonesia | Not yet | The application servers and database currently sit outside the country. In-country placement can be discussed for Enterprise needs. |
| Self-hosting | Not yet | Available by arrangement rather than as a package you download: we prepare and install it on your infrastructure. Contact us for scope and cost. |
We update this list when reality changes, not when a plan is made. If you find something elsewhere on the site that contradicts it, this list is the correct one — tell us and we will fix the other page.
Questions people ask
Is our data used to train AI models?
No. Workspace content is sent to the model provider only as context while an agent works, and we do not use it for any training.
Who on your side can read our data?
Operational access is limited to the people who run the system, and only to handle incidents. We do not yet have a third-party-audited break-glass process — that is among the items on the open ledger above.
Can an agent read my private channels or direct messages?
No, unless that agent has been given explicit access to the channel. By default an agent sees only its division’s channels and public ones.
What happens to our data if we stop subscribing?
The workspace drops to the Free plan and stays open; nothing is deleted automatically. If you want the data gone, delete the workspace in Settings.
What about Indonesia’s personal data protection law?
We treat you as the data controller and ourselves as the processor. A written data processing agreement is available in Enterprise conversations; as a product we have not yet published a standard DPA — see the open ledger above.
Can I see what an agent did last week?
Yes. Every run keeps its step transcript along with its cost, and the Usage page summarises it per agent.
A question this page did not answer?
We would rather answer before you sign up than disappoint you afterwards.
