Skip to content

Security, built in from the start

The Chat Agent is built on the assumption that your conversations, credentials, and configuration are sensitive. Encryption, access controls, data isolation, and responsible data handling are not add-ons — they are foundations of the platform.

Security model

Every layer, secured

From the token in your browser to the bytes in your database, each layer of The Chat Agent is designed to protect your data.

Authentication & sessions

Secure sign-in with hashed passwords and signed session tokens, CSRF protection, and brute-force rate limiting — all handled for you out of the box.

  • Hashed passwords and signed session tokens
  • Secure HTTP-only session cookies
  • Brute-force rate limiting

Role-Based Access Control

Granular RBAC ensures users only access the resources their role permits — from admin to read-only member — across every workspace.

  • Admin, Manager, and Member roles
  • Per-workspace permission scopes
  • Instant deprovisioning

Encrypted API Keys at Rest

Provider API keys are encrypted before storage. The plaintext key never persists unprotected, and keys are never exposed in application logs or API responses.

  • AES-256 encryption at rest
  • Per-account key isolation
  • Keys never exposed in logs or responses

Data isolation

Your account operates in a fully isolated data context. Conversation history, uploaded files, and configurations are scoped to you and never mixed with another user's data.

  • Strict per-account data scoping
  • Export or delete your data on demand
  • No cross-account data access

Encryption in Transit

All communication between clients, the API, and upstream AI providers is protected with TLS 1.2+. WebSocket connections are encrypted end-to-end.

  • TLS 1.2 and 1.3 enforced
  • HSTS headers included
  • Encrypted WebSocket connections

No Training on Your Data

The Chat Agent never uses your conversations to train or fine-tune AI models. We maintain strict data-use policies with all provider integrations and your prompt content is never forwarded for training purposes.

  • Provider data-use clauses respected
  • No training on your conversations
  • Prompt content never used for model training

Your data, protected

Your data stays yours

Every conversation, uploaded file, and configuration value in The Chat Agent is encrypted at rest using AES-256. Data is backed up automatically and never accessible to third parties outside of your account boundary.

Provider API keys — for OpenAI, Anthropic, Google Gemini, Azure OpenAI, and others — are encrypted before storage and decrypted only at the moment a request is made. Keys are never written to logs, never returned in API responses, and are fully isolated per account.

Role-based access controls let you decide exactly who can see and do what in a shared workspace, so every member is scoped to the resources their role permits.

We never train on your data

The Chat Agent never uses your conversations, prompts, or uploaded files to train or improve AI models. We enforce strict data-use agreements with all integrated providers, and no conversation content is forwarded for training purposes.

Responsible disclosure

Found a vulnerability?

We take security reports seriously. If you discover a vulnerability in The Chat Agent — whether in the application, the API, or our platform infrastructure — please disclose it responsibly. Reach out via our contact page with a clear description of the issue and steps to reproduce it. We aim to acknowledge all reports within two business days and will work with you on a coordinated fix and disclosure timeline.

Ready to get started with secure AI chat?

Connect your providers, invite your team, and chat with AI — with security built in at every layer.