Security without inflated claims

Your client relationships deserve clear, practical safeguards.

This page describes controls that are currently implemented in AgentOS. For a security questionnaire or a requirement not covered here, contact us before relying on it.

Protected sessions

AgentOS issues signed sessions in server-set, HTTP-only cookies. Production and preview cookies are also restricted to secure connections.

Password protection

Passwords are processed with bcrypt. AgentOS does not store or return a plain-text password after account creation.

Account-scoped access

Authenticated sessions include an account identifier, and protected CRM page requests validate the user and account relationship before loading the workspace.

Fail-closed internal tools

Internal test and billing-debug endpoints are unavailable in Preview and Production and return a generic not-found response.

Our standard

Trust is built with precision.

AgentOS will describe a safeguard only when it can be demonstrated. This is a current-state overview, not a blanket certification or legal guarantee.

  • We do not publish compliance or certification claims that have not been independently verified.
  • We do not expose session tokens in the browser-readable login response.
  • We avoid placing customer identifiers or session contents in routine login logs.
  • We keep this overview limited to safeguards backed by the current implementation.

Have a security requirement?

Ask before you buy. We will give you a direct answer about the current product, data handling, retention, export, and integration scope.

Contact security