Security
Agents move fast inside hard limits. These are the limits.
One computer per agent
Every agent runs on its own isolated cloud computer with a browser. One agent's files, sessions and logins are never another's. Each customer's whole team runs in its own cell: agents, computers, vault and files, isolated from every other customer.
Keys scoped per repo
Credentials live in an encrypted vault. Each key is scoped to a repo or an org, and an agent gets only the keys for the repo it's working in. Values never appear in chat, logs or reports; agents see a placeholder that the vault fills in on the way out.
A passkey guards the vault
Add a passkey (Face ID, Touch ID or Windows Hello) in Settings and the vault stops trusting a signed-in session alone. Changing or revealing a key, making an API key, adding an MCP server and approving a purchase each need a fresh proof from your own device, checked on the server, every time: one change, one Face ID, like a payment in a bank app. The iPhone and Mac app also lock behind Face ID, Touch ID or your passcode when you open them and after they've been in the background. A stolen session, an API key or a Claude client can't do them: a Claude client's key change waits for your approval on your phone, and a key pasted into chat is taken out of the chat but only the app can add it. Recovery codes and a 24 hour cancellable wait cover a lost device. Every grant, refusal and reveal is logged in Vault activity.
Nothing goes out without your yes
- Emails, texts, calls and posts wait as drafts. You can edit them before you tap Send.
- Builds start only after you approve the plan.
- Purchases need your own swipe and a hold on your phone. A chat message can't approve a payment.
Your data
We don't train models on your content, and we don't sell or share your data for advertising. Delete your account from Settings and your cell, vault, files, chats and history go with it. See the Privacy Policy and the Data Processing Agreement.