Legal

Security is part of the product

Access control, audit logging and encryption are in the core platform on every plan. They are not held back as a gate for enterprise contracts.

How we protect your workspace

Encryption

TLS 1.2 or better in transit and AES-256 at rest for databases and file storage. Integration credentials and your LLM key are encrypted at the field level.

Access control

Workspace-scoped roles on a five-level ladder, from owner to viewer. Custom roles, per-resource grants and multi-factor authentication are not available yet.

Infrastructure

Hardened hosting, network segmentation, automated encrypted backups and least-privilege internal access.

Audit logging

Every mutating action is written to a filterable activity log, so you can see who did what and when.

AI agent guardrails

The agent runs on your LLM key and is bounded by the API-key scopes you grant. Every action is logged and reversible.

Vulnerability management

Continuous dependency scanning, rapid patching and periodic third-party testing.

Regulatory posture

GDPR and UK GDPR

Data processing agreements, access and deletion workflows, and Standard Contractual Clauses for cross-border transfers.

CCPA and CPRA

Consumer access and deletion rights, no sale of personal data, and disclosure of automated processing such as fit scoring.

We hold no formal certification yet; they are pursued as we scale. Current attestations and our data processing agreement are available on request during an evaluation. See also the privacy policy.

Responsible disclosure

Found something? Write to security@outboundrix.com. We acknowledge reports within 48 hours and will not pursue good-faith researchers.