Home/Security

Security is the architecture.
Not a badge.

Deployment sovereignty, scoped credentials, and a complete audit trail come standard on every plan — including free.

Access control

Least-privilege agent keys

Agents get send-only keys. No PII export, no domain changes, no billing access, no admin actions. Scopes, rate limits, and approval gates ride on the key itself — revoke an agent without touching your app.

api keys — growth-bot
🔑 sfk_agent_9f2e… · growth-bot
email:sendcontacts:readbroadcast:draft✕ domains✕ export✕ billing
Rate limit 100/hr · Approval gate broadcasts > 250 · Expires 90d
audit log — exportable CSV
14:02:11email.sent · invoice #4821billing-svc
14:01:58gate approved · broadcast > 250admin (human)
13:58:40agent key rotatedadmin
13:44:02domain verified · acme.comadmin
13:41:19segment created · "inactive 30d"growth-bot
Accountability

Every action attributed

Every send, approval, key change, and agent action is logged with actor, timestamp, and result. Human decisions are distinguishable from agent actions — always.

Export the full trail as CSV for your SIEM on every plan. Immutable append-only storage in self-hosted deployments.