Security model

Who can write what, and how the boundaries are enforced. Summary of the properties the system guarantees; the marketing security page has the narrative version.

Written from the code · updated 26 Sep 2026 · Something wrong or missing? Tell us

Write authority

  • The agent under test or under guard never holds provider write credentials. Only COLVO’s worker (the executor) writes to Stripe, and only after the policy allowed or a human approved.
  • Mandates come from your trusted backend with a backend key; an agent key can only propose and read.
  • Per-attempt agent keys are minted for test runs and scoped to that attempt.

Tenant isolation

Every tenant table has Postgres row-level security keyed on the organisation set by the authenticated session or key. The application database role cannot bypass it; cross-organisation reads return nothing and writes are refused. The same holds in the worker and in exports.

Roles

  • Org roles: owner (billing, keys, members, deletion), editor (configure, run, approve), viewer (read).
  • Superadmin (COLVO staff) is exclusive: never a member of a client organisation, works in a separate console, and every action is logged.

Network

Outbound calls, including the call to your agent, go through an egress policy: allow-listed hosts, localhost / private / cloud-metadata ranges blocked, DNS pinned, redirects re-checked, 30-second timeouts and body limits.

Secrets and evidence

  • Provider keys, webhook secrets, agent auth headers and AI keys are encrypted at rest per organisation and never appear in logs, prompts or exports.
  • API keys are stored as SHA-256 hashes, shown once; rotate from Settings.
  • Evidence and usage tables are append-only for the application role; deletion happens only through an audited gate on the owner connection (organisation deletion, retention).

Idempotency and reliability

Business key + budget reservation + transactional outbox; no open database transaction across a network call; reconciliation from provider state after crashes, timeouts and provider review. A retry never doubles an effect.

Reporting

Vulnerabilities: [email protected]. See the security page for scope and response times.

Security model · Docs · COLVO