What is true today.
An autonomous workforce needs the same things a human one does before it touches real systems: its own credentials, a limit on what it can spend, and a record of what it did. This page says which of those are in place, which are not, and where to check.
Per-agent identity
Scoped connections
Audit of every action
Spend caps and budgets
Keys wrapped at rest
Data handling
Only what a spec says. Nothing here is a certification; the day one starts, this section changes.
Tamper-evident audit export
Certifications
Self-serve data export
If you find a vulnerability, email security@connect0.ai (hi@connect0.ai also reaches us). Tell us what you found and how to reproduce it; we acknowledge within two business days, keep you informed while we fix it, and credit you if you want to be credited. Please give us a reasonable window before publishing, and do not access data that is not yours. We do not run a paid bounty programme today; we will say so here if that changes.
Email security@connect0.aiControl by control, with evidence.
| Control | Status | Evidence |
|---|---|---|
| Per-agent identity and scoped credentials | In place Each agent is a principal; access is per agent, per resource, default-closed. | Access model |
| Scoped third-party connections | In place Credentials held centrally; each agent gets only the scopes granted. | About connectors |
| Server-side audit of every action | In place Tool calls, shell commands, accesses — including failures — recorded and exportable. | Audit |
| Spend caps, budgets, fail-closed on empty wallet | In place Hard cap per account, budgets per project or agent, price published before each action. | Spend controls |
| Provider keys and connection credentials KMS-wrapped at rest | In place Envelope encryption with a cloud KMS key; plaintext never stored. | Bring your own key |
| Sandbox output never logged | In place Command, exit code and duration are recorded; stdout, stderr, env and files are not. | Privacy notice §2.3 |
| Payment data held by the processor | In place Stripe holds cards and addresses; connect0 stores ids and invoice metadata only. | Privacy notice §2.4 |
| Session and OAuth-grant revocation | In place Active sessions and grants are listed and revocable from the dashboard; tokens stored as hashes. | Privacy notice §2.5 |
| Ledger postings append-only with a hash chain | In place The ledger block chains postings per book; corrections are reversals, never edits. | connect0 Blocks |
| Tamper-evident (WORM) platform audit export | Not yet The platform audit log is complete and server-side, not yet a hash-chained WORM export. | Audit |
| Self-serve data export (DSAR) | Partial Handled by email at privacy@connect0.ai; not yet self-serve in the dashboard. | Privacy notice |
| SOC 2 / ISO 27001 / HIPAA | Not yet Not certified; no audit in progress. This page changes the day one starts. | Ask us |
Not yet certified. This table is the substitute until a certification exists — every row links the page that proves it. Machine-readable version: curl -H 'Accept: text/markdown' https://connect0.ai/safety