Security and privacy
These are the controls implemented in the engine and tested in its suites. We do not claim certifications we have not obtained, and a passing audit is not the same as a security guarantee.
- Tenant isolation
- Every tenant object is row-level-secured with FORCE RLS and a dedicated non-superuser runtime role. Cross-tenant reads return 404, never existence.
- Capability-scoped execution
- Connected components and agents receive short-lived capabilities for declared tools only; everything else is permission_required.
- Secrets
- Model and provider credentials are read from the environment or a secret store and never logged, rendered, exported or placed in URLs. Exports refuse archives containing credential fields.
- Supply chain
- Dependency install scripts are explicitly denied at install time. Release artifacts are digest-addressed and signed; SBOMs are generated per release.
- Untrusted content
- Repositories, issue text and model output are data, never instructions. They cannot change policy or grant permissions.
- Sandboxing
- Local execution is a bounded, env-scrubbed runner for owner-trusted use; untrusted multi-tenant code requires a remote managed sandbox adapter.
- Licence integrity
- AGPL components publish corresponding source; permissive browser packages never bundle AGPL server code or credentials.
Report a vulnerability
Send reports to security@docsloth.com with reproduction steps. We acknowledge within two business days, keep you updated, and credit reporters who want it. Please do not test against customer data or degrade live service.
Actions
Actions
- Report vulnerability
Opens your mail client to security@docsloth.com. No account or payment; acknowledgment within two business days.
- Read subprocessors
Lists the provider categories and when each is enabled for a deployment; no subprocessors are enabled in this build.