Security and compliance
How hosted artifact protection, deletion, audit records, and authentication safeguards work.
Last updated: August 20, 2026
What is in place
Hosted artifact copies use envelope encryption. Without the deployment artifact key, durable uploads are disabled.
See the Data Processing Agreement for the governing terms.
Hosted MCP tool results that carry captured application content wrap that content in an untrusted evidence block delimited by a per response nonce, so a reading model can tell captured data from instructions.
See the Data Processing Agreement for the governing terms.
Connector secrets are sealed with a separate key and cannot be read back, including by us.
See the Data Processing Agreement for the governing terms.
Organization administrators can request account and data subject deletion through the API. Project deletion runs as a resumable job from the dashboard and produces a receipt.
See the Data Processing Agreement for the governing terms.
Retention is keyed to your plan, and purge runs are measured and audited.
See the Data Processing Agreement for the governing terms.
Per project redaction levels apply before evidence leaves the capture boundary, including per tenant keyed hash redaction.
See the Data Processing Agreement for the governing terms.
Administrative changes have a tenant audit trail, readable and exportable as CSV through the API. Data access and agent reads are audited separately.
See the Data Processing Agreement for the governing terms.
Authentication surfaces are rate limited, and ingest carries tier scaled rate limits and per project capture budgets.
See the Data Processing Agreement for the governing terms.
Model egress is bounded by a daily byte budget and a manual kill switch, with an optional per tenant ceiling.
See the Data Processing Agreement for the governing terms.
Known limits
Stated here rather than left for you to find in a trial.
Encryption at rest on the local capture volume is off by default. Even when it is on, the live event log and any media uploaded during capture stay readable until the session is finalized.
Hash redaction is pseudonymization rather than anonymization. The same raw value can receive different digests at different finalization points.
Account deletion, data subject deletion and deletion receipts have a dashboard screen, under Settings, Data and privacy. The audit trail export is still reachable through the API only, so taking a copy of it before an account deletion means calling the API as your organization administrator.
SAML single sign on and directory sync are set up with our team rather than from the dashboard. We generate the setup link for an eligible tenant, and your administrator finishes the connection in the identity provider's own hosted portal. There is no self serve activation screen yet. Directory sync events suspend, reinstate, and revoke access for existing members; they never create a member record, which appears when that person first signs in and their verified email domain matches your tenant. That identity provider is one of our subprocessors: the full list, what each one receives, and where we have not yet executed a data processing agreement are in our Privacy Policy and in Annex C of our Data Processing Agreement.