Security

Security you can
trust.

Your data, your code, your business. Protected at every layer by sandboxed execution and zero-trust architecture.

Architecture

Encrypted in transit

All API calls and data transfers use TLS 1.3. No exceptions, no fallbacks.

Encrypted at rest

All stored data is encrypted with AES-256. Keys are managed via hardware security modules.

Sandboxed execution

Each agent runs in an isolated sandbox where it can operate freely without risking anything outside its defined boundaries. No permission prompts, no interruptions.

Data handling

01

No training on your data

We never use your prompts, code, or outputs to train models. Your data is yours. Period.

02

Minimal retention

We retain only what's needed for your session. Logs are automatically purged according to your plan's retention policy.

03

Provider passthrough

When routing to model providers, we pass your request through without storing the payload. Each provider's data policies apply independently.

04

Audit logs (Enterprise)

Enterprise customers get complete audit logs with retention covering every agent action, every API call, and every file access, for compliance and review.

Access control

You define the boundaries

Set the sandbox scope for files, commands, and network access. Agents operate freely within those boundaries. The environment itself is safe, so you never need a permission wall blocking every action.

API key management

Create, rotate, and revoke API keys from your dashboard. Set per-key permissions and rate limits.

Have a security concern or want to report a vulnerability? Contact us at security@gotmode.com.

Enterprise security needs?

SSO, SLA guarantees, and a dedicated account team.