Security

Safe by design

We prioritize the safety and integrity of your data above all else.

Encrypted credentials

Stored credentials are encrypted with AES-256-GCM, and every connection to Gridable uses TLS.

Your workspace, sealed

Every record, file and query is scoped to your workspace. The server refuses cross-workspace access.

Whoever asked, decides

Most tools that send, publish or change something outside your workspace pause for the person who asked. A send inside a standing send-as-me grant that person gave goes without a per-send approval, and a few older tools are not yet gated. When a run itself takes in text nobody in your workspace wrote, those tools are refused for that run. In a later message in the same conversation, they pause instead for the person who asked, and are refused when nobody is watching.

Tokens stay out of reach

OAuth tokens for your connected tools are held by our self-hosted connection broker, never placed in an agent's context.

No training on your data, by default

By default, every request made for your workspace through OpenRouter may be served only by a host that does not store or train on it. Claude and OpenAI models called directly run under Anthropic's and OpenAI's API terms, which do not use API data for training. A workspace admin can opt out in Settings. Questions Gridable's decision model answers about your work go only to hosts that keep nothing, whatever that setting says.

Every run on the record

Each workflow and agent run leaves a record of what ran and what it produced, and every action that waits for approval records who approved it.

The full list of controls, each with its status and what we do not have yet, is on the trust page.

Found a vulnerability?

We operate a responsible disclosure program. If you believe you have found a security vulnerability in Gridable.ai, please report it to us immediately. The scope, the safe harbour and a report form are on the trust page.

Submit Report