Security
How sessions are designed. Written in the present tense because this is how the service is built to behave; detailed documentation goes to early-access members on request.
Devices
- Shared devices are factory-reset and re-provisioned between sessions. No app, account or file survives.
- Private devices belong to one workspace and are never pooled.
- Your own devices stay on your network; the connector opens an outbound connection only.
Data
- We store no app credentials. Secrets your agent types go to the device, not to us.
- Builds you upload are deleted when the session ends unless you choose to keep them.
- Screenshots, video and logs are yours; retention is configurable per workspace, default 30 days.
Access
- One bearer token per workspace, rotatable at any time.
- Sessions have a maximum length; idle sessions are released automatically.
- Every session is attributable: which token, which device, when.
Compliance
Security questionnaires, data-processing terms and a current architecture overview are available to early-access members on request. Formal certifications follow general availability. Deciding whether to trust us at all? What exists today and what doesn't.