Protected sessions
AgentOS issues signed sessions in server-set, HTTP-only cookies. Production and preview cookies are also restricted to secure connections.
This page describes controls that are currently implemented in AgentOS. For a security questionnaire or a requirement not covered here, contact us before relying on it.
AgentOS issues signed sessions in server-set, HTTP-only cookies. Production and preview cookies are also restricted to secure connections.
Passwords are processed with bcrypt. AgentOS does not store or return a plain-text password after account creation.
Authenticated sessions include an account identifier, and protected CRM page requests validate the user and account relationship before loading the workspace.
Internal test and billing-debug endpoints are unavailable in Preview and Production and return a generic not-found response.
Our standard
AgentOS will describe a safeguard only when it can be demonstrated. This is a current-state overview, not a blanket certification or legal guarantee.
Ask before you buy. We will give you a direct answer about the current product, data handling, retention, export, and integration scope.