Security

How Veflow handles your code and data.

Read how cloud runtimes, repository permissions, and database access are separated, and what changes when you run agents locally.

Data flow

Where your code runs and gets processed.

Desktop sessions run against local files. Managed cloud runs use Veflow infrastructure. In either mode, an agent may send context to its model provider.

Local · bring your own agent

Your CLI runs on your machine using your agent subscription or API key. Veflow does not host the local checkout. The agent may send code and context to its model provider.

  • Code, diffs, and terminal output never touch our servers.
  • We sync only session metadata: repository and branch names, timestamps, and status.
  • Development processes run on your machine. Model requests follow your chosen agent’s configuration.

Managed · cloud runs

For a managed cloud run, Veflow clones your repository into an isolated container. The task stores the agent conversation and diffs for review. Preview runtimes may remain available after the agent finishes.

  • Cloud runtimes are isolated and removed when their lifecycle ends.
  • The agent conversation and diffs are saved to the workspace for review and can be deleted with the associated record.
  • Prompts go to your model provider (Anthropic or OpenAI) over TLS and, per their API terms, are not used to train their models.

Read the data-handling details

The Privacy Policy describes the data Veflow processes and stores. Your chosen agent provider’s terms also apply to the context sent to its models.

How we protect your code and data.

  • Isolated per-tenant runtimes

    Every workspace and preview runs in its own sandboxed cloud container. One tenant's code can't reach another's files, processes, memory, or network.

  • Least-privilege GitHub access

    Tokens are scoped to a single repo with only the permissions a task needs. Master keys stay on our edge. They never touch your code or dependencies.

  • Secrets stripped from untrusted code

    Veflow removes infrastructure credentials from the environment used by project dependencies and development scripts.

  • Encrypted environment variables

    The env vars you add are sealed with authenticated encryption before they're stored, and the key is held off the database, so backups and exports only ever hold scrambled text. They're decrypted only server-side, at boot, to write the .env inside your isolated workspace, and never shown again.

  • Row-level security by default

    Your data sits behind Postgres row-level security, scoped per workspace and enforced at the database, not just the app layer.

  • Encrypted in transit

    Every connection (app, preview tunnel, and API) is served over TLS. Preview URLs run behind per-task tunnels on our edge, not open ports; the in-browser IDE and dev tunnels add a signed-in membership check on top.

  • Attributable audit trail

    Every decision, edit, comment, and status change lands in a durable, attributable activity feed. Weeks later you can still see who did what, and why.

  • Your code isn't training data

    Inference runs on the Anthropic API under terms that exclude training on your data. Agent runners are ephemeral: your repo is cloned for the run and destroyed with the container. What persists is the task record you already see: plans, diffs, comments.

Built for the GDPR.

You can access, export, correct, or delete your data at any time. Every processing purpose, sub-processor, and international-transfer safeguard is documented in our Privacy Policy.

Read the Privacy Policy

Questions about security or compliance?

We're happy to walk through our architecture, data handling, and roadmap. SAML, a security review, and self-host options are available on Enterprise.

Talk to us