Security • Privacy • Auditability

Trust, Engineered In

AI agents act on real systems with real credentials, so we treat security as a product feature, not a page of promises. Here's how ApiSpi protects your keys, your data, and your users โ€” and how you can verify it.

๐Ÿ”‘

Credentials encrypted at rest

Connector tokens, OAuth secrets, and provider keys are stored encrypted and never serialised into pages or logs. Secret fields are write-only in every admin screen.

๐Ÿ”’

Hardened transport & headers

HTTPS enforced with HSTS, plus a strict Content-Security-Policy, frame, MIME, referrer, and permissions headers on every response.

๐Ÿ›ก๏ธ

Layered guardrails

Input and output guardrails, prompt-injection screening, content moderation, blocked-keyword redaction, and policy-as-code rules โ€” enforced on chat, gateway, MCP, and A2A alike.

โœ‹

Least privilege for tools

Per-tool disable switches, read-only and approval modes for state-changing actions, connector kill switches, and an organisation-wide emergency stop.

๐Ÿงพ

Everything on the record

Every significant action lands in the activity log with actor attribution; governance events export to CSV or stream HMAC-signed to your SIEM in real time.

๐Ÿ‘ค

Account security

Two-factor authentication with recovery codes, Google and Microsoft single sign-on, scoped API keys you can rotate at any time, and admin-only surfaces behind role checks.

Found something?

We take reports seriously and respond fast. If you believe you've found a security issue in ApiSpi, please contact us with the details โ€” we'll acknowledge receipt and keep you updated through the fix.

Security Questions Before You Commit?

We'll walk your security reviewers through the stack, control by control