Security

We don't store your passwords.

Because there aren't any. untactit authenticates through your existing identity provider, which means there is no password database here to breach.

No password storage

Sign-in goes through Google, Microsoft, or your SAML provider. We never see, hold, or transmit a password — there is no credential table to steal.

Tenant isolation

Every record carries its organization. Queries are scoped at the data layer, not filtered in the interface — a missing filter fails closed, not open.

Append-only audit

Who changed what, when, and from where. Entries are written once and never edited — including by us.


Access control

Permission is decided by the server on every request. The interface reflects that decision — it never makes its own.

  • Four roles with distinct capability sets, not a single admin flag
  • Signed, expiring sessions — no long-lived shared tokens
  • Invitations expire in seven days and can only be used once
  • Domain-based joining is opt-in per organization, never automatic

Identity providers

Google Workspace
OAuth 2.0 · OIDC
Available
Microsoft Entra ID
OAuth 2.0 · OIDC
Available
SAML 2.0
Okta, OneLogin, and others
Enterprise
SCIM provisioning
Automatic deprovisioning
Enterprise

In transit

TLS 1.2 or higher on every connection, including internal service traffic.

At rest

Encrypted storage volumes with managed keys. Backups inherit the same encryption.

Sensitive fields

Vendor credentials are encrypted at the application layer with a separate key, so a database dump alone does not expose them.

Data handling

Disk-level encryption stops a stolen drive. It does not stop a leaked backup or an over-broad query, so we encrypt sensitive fields separately.

  • Your assets are yours — we don't train anything on them
  • Export everything, any time, in an open format
  • Deletion removes data rather than hiding it behind a flag
  • Regional data residency available on Enterprise

Being straight with you

Security pages usually list certifications. Here's where we actually are.

  • In place today — SSO-only authentication, role-based access enforced server-side, append-only audit logging, tenant isolation at the data layer, application-level encryption for credentials.
  • ×Not yet — SOC 2 Type II. We're early, and claiming otherwise would be the kind of thing this product exists to prevent. If your procurement process requires it, tell us and we'll give you a real timeline.

Security questions, disclosure reports, or a DPA request — get in touch. We answer security mail before we answer sales mail.

Stop guessing what your agents are running.

Connect one workspace and see every skill, rule, and memory your team has in play — in about ten minutes.

Start free Talk to us

No credit card. Works with what you already run.