Security

Trust for autonomous work

When AI touches email, spreadsheets, and production systems, governance isn't optional. OWeb builds approvals, audit, and org isolation into the workspace — not as an afterthought.

Org isolation

Multi-tenant architecture with workspace-scoped data. Your workspace, memory, and artifacts are isolated from other customers.

Role-based access

Team roles control who can run agents, connect integrations, approve actions, and view audit history.

Approvals

Sensitive agent actions can require human approval before execution — so speed doesn't mean surprises.

Audit logs

Track what ran, who triggered it, and what changed. Essential for ops teams and compliance-minded buyers.

Integration credentials

OAuth and scoped tokens for connected apps. Credentials are stored securely and scoped to your workspace.

Encryption

Data encrypted in transit (TLS) and at rest via our infrastructure providers. Industry-standard key management.

Infrastructure

Built on proven platforms

We use best-in-class providers so you inherit their security investments.

Supabase

Database & auth infrastructure

Vercel

Application hosting & edge

Stripe

Billing — PCI handled by Stripe

Compliance roadmap

We are not SOC 2 certified today. We are actively preparing controls aligned with SOC 2 Type II — access management, change control, logging, and vendor review. We will update this page when certification is complete. We would rather be honest than over-claim.

Enterprise buyers: contact us for security questionnaires, DPA requests, and architecture reviews.

Data handling principles

  • · Your org data is not used to train foundation models
  • · You control which integrations connect and what scopes they receive
  • · Audit logs help you understand agent and automation activity
  • · Account deletion requests are honored per our data retention policy
Explore the product

Autonomous work with guardrails

Start free. See approvals, audit, and org isolation in your workspace.