Agentcess

Security

How Agentcess protects your workspace: passkey-verified approvals, row-level isolation, sealed evidence chains and automatic containment.

Agentcess is itself a security product, so our own controls are held to the same standard we enforce on your agents.

How your workspace is protected

  • Every workspace is isolated at the database level with row-level security; no account can read another workspace's records.
  • Sign-up is invite-only, and approvals are verified with device passkeys — a decision always names the person who made it.
  • Tool credentials are stored server-side and are never handed to an agent; the agent receives results, not secrets.
  • Evidence is sealed into a hash-chained record book; altering history breaks the chain and is detectable on verification.

How your agents are contained

  • Every action passes the gate: identity, capability, risk tier, policy, zone and budget checks in a fixed order.
  • Destructive and consequential capabilities always require a person's confirmation.
  • An agent turned away repeatedly is placed on hold automatically, with the reason written to its identity history.
  • Emergency stop revokes an agent's authority in one step.

Reporting a vulnerability

If you believe you have found a security issue in Agentcess, write to security@agentcess.com. We ask that you give us a reasonable window to investigate and fix before any public disclosure.