agentdbaas

Security

Security

We run the backend, so we carry most of the security work. We hold the account, scope credentials per agent, take backups, and record every agent run.

The account

Who holds the account.

We hold the cloud account and run the resources. There is no console for you to learn. You do not manage keys or servers, because we do that for you.

Credentials

Each agent gets its own scoped credentials over plain HTTP. The credentials reach only what that agent needs. One agent cannot use another agent's access.

What we record

We record every agent run in the Agent Flight Recorder. This covers every session, tool call, model turn, and cron beat, against the agent that made it. The record is sequenced, timestamped, and append-only. The Flight Recorder page describes the tape.

Encryption

Prompts and tool output are encrypted before they leave the host. The backend stores ciphertext and has no private key. You hold the key, so we cannot read the content.

Backups

We take backups. This keeps your data safe if a resource fails.

Access changes

Access changes are a request to us. You email us, and we change access. There is no console for you to manage.

Get access Read the Flight Recorder