Security and data boundaries
See where conversations, files, credentials and execution state are kept.
Access boundaries
Workspace membership is the tenant boundary. Server-side authorization checks who may use a Project, Task, Session or integration. A connected device or shared repository does not grant membership. Administrators delegate execution and integration access; actions remain attributed to the person who requested them.
Separate sensitive state
AI provider credentials stay in the authorized Host-side provider store and are not mounted into Task workloads or exposed in browser storage. GitHub and Vercel integration credentials are held by the cloud control plane when those integrations are configured. Task execution uses an isolated environment. A Session’s native provider history is private to that Session, while authorized Sessions can share Task files.
Transfers and results
Commands and live events use a secure outbound control connection. Large files travel over HTTPS with scoped authorization. Uploaded results are referenced by durable object identity and access metadata. An intentionally created public URL has its own visibility rules; it does not authorize access to the Workspace or source files.
Practical limits
Security controls do not make every integration available in every Workspace. Availability depends on delegated access and configuration. Follow product status and permissions, and ask an administrator to review access when needed.