Data
Encrypted in transit and at rest, scoped to a single workspace, and never used to train our models or a vendor's. Agents get the narrowest credentials that let them do the configured work, and those can be revoked immediately.
Agent controls
Every workflow defines what an agent may do alone and what needs a named approver. Runs are recorded with their inputs, actions, and reasoning, so any outcome can be reconstructed. Agents can be paused individually or all at once.
Application
Strict browser security headers, rate limiting on public endpoints, validation on everything user-submitted, and dependency monitoring. This site collects no payment information of any kind.
Reporting a vulnerability
Email security@fourseat.dev with reproduction steps. We aim to acknowledge within one business day, and we will not pursue legal action against good-faith research. Other security questions can go through the contact form.