Safety

What is true today.

An autonomous workforce needs the same things a human one does before it touches real systems: its own credentials, a limit on what it can spend, and a record of what it did. This page says which of those are in place, which are not, and where to check.

Responsible disclosure

If you find a vulnerability, email security@connect0.ai (hi@connect0.ai also reaches us). Tell us what you found and how to reproduce it; we acknowledge within two business days, keep you informed while we fix it, and credit you if you want to be credited. Please give us a reasonable window before publishing, and do not access data that is not yours. We do not run a paid bounty programme today; we will say so here if that changes.

Email security@connect0.ai
Compliance status

Control by control, with evidence.

Compliance status by control
ControlStatusEvidence
Per-agent identity and scoped credentialsIn place

Each agent is a principal; access is per agent, per resource, default-closed.

Access model
Scoped third-party connectionsIn place

Credentials held centrally; each agent gets only the scopes granted.

About connectors
Server-side audit of every actionIn place

Tool calls, shell commands, accesses — including failures — recorded and exportable.

Audit
Spend caps, budgets, fail-closed on empty walletIn place

Hard cap per account, budgets per project or agent, price published before each action.

Spend controls
Provider keys and connection credentials KMS-wrapped at restIn place

Envelope encryption with a cloud KMS key; plaintext never stored.

Bring your own key
Sandbox output never loggedIn place

Command, exit code and duration are recorded; stdout, stderr, env and files are not.

Privacy notice §2.3
Payment data held by the processorIn place

Stripe holds cards and addresses; connect0 stores ids and invoice metadata only.

Privacy notice §2.4
Session and OAuth-grant revocationIn place

Active sessions and grants are listed and revocable from the dashboard; tokens stored as hashes.

Privacy notice §2.5
Ledger postings append-only with a hash chainIn place

The ledger block chains postings per book; corrections are reversals, never edits.

connect0 Blocks
Tamper-evident (WORM) platform audit exportNot yet

The platform audit log is complete and server-side, not yet a hash-chained WORM export.

Audit
Self-serve data export (DSAR)Partial

Handled by email at privacy@connect0.ai; not yet self-serve in the dashboard.

Privacy notice
SOC 2 / ISO 27001 / HIPAANot yet

Not certified; no audit in progress. This page changes the day one starts.

Ask us

Not yet certified. This table is the substitute until a certification exists — every row links the page that proves it. Machine-readable version: curl -H 'Accept: text/markdown' https://connect0.ai/safety