Security, built in from the start
The Chat Agent is built on the assumption that your conversations, credentials, and configuration are sensitive. Encryption, access controls, data isolation, and responsible data handling are not add-ons — they are foundations of the platform.
Security model
Every layer, secured
From the token in your browser to the bytes in your database, each layer of The Chat Agent is designed to protect your data.
Authentication & sessions
Secure sign-in with hashed passwords and signed session tokens, CSRF protection, and brute-force rate limiting — all handled for you out of the box.
- Hashed passwords and signed session tokens
- Secure HTTP-only session cookies
- Brute-force rate limiting
Role-Based Access Control
Granular RBAC ensures users only access the resources their role permits — from admin to read-only member — across every workspace.
- Admin, Manager, and Member roles
- Per-workspace permission scopes
- Instant deprovisioning
Encrypted API Keys at Rest
Provider API keys are encrypted before storage. The plaintext key never persists unprotected, and keys are never exposed in application logs or API responses.
- AES-256 encryption at rest
- Per-account key isolation
- Keys never exposed in logs or responses
Data isolation
Your account operates in a fully isolated data context. Conversation history, uploaded files, and configurations are scoped to you and never mixed with another user's data.
- Strict per-account data scoping
- Export or delete your data on demand
- No cross-account data access
Encryption in Transit
All communication between clients, the API, and upstream AI providers is protected with TLS 1.2+. WebSocket connections are encrypted end-to-end.
- TLS 1.2 and 1.3 enforced
- HSTS headers included
- Encrypted WebSocket connections
No Training on Your Data
The Chat Agent never uses your conversations to train or fine-tune AI models. We maintain strict data-use policies with all provider integrations and your prompt content is never forwarded for training purposes.
- Provider data-use clauses respected
- No training on your conversations
- Prompt content never used for model training
Your data, protected
Your data stays yours
Every conversation, uploaded file, and configuration value in The Chat Agent is encrypted at rest using AES-256. Data is backed up automatically and never accessible to third parties outside of your account boundary.
Provider API keys — for OpenAI, Anthropic, Google Gemini, Azure OpenAI, and others — are encrypted before storage and decrypted only at the moment a request is made. Keys are never written to logs, never returned in API responses, and are fully isolated per account.
Role-based access controls let you decide exactly who can see and do what in a shared workspace, so every member is scoped to the resources their role permits.
We never train on your data
The Chat Agent never uses your conversations, prompts, or uploaded files to train or improve AI models. We enforce strict data-use agreements with all integrated providers, and no conversation content is forwarded for training purposes.Responsible disclosure
Found a vulnerability?
We take security reports seriously. If you discover a vulnerability in The Chat Agent — whether in the application, the API, or our platform infrastructure — please disclose it responsibly. Reach out via our contact page with a clear description of the issue and steps to reproduce it. We aim to acknowledge all reports within two business days and will work with you on a coordinated fix and disclosure timeline.
Ready to get started with secure AI chat?
Connect your providers, invite your team, and chat with AI — with security built in at every layer.