AI agents act on real systems with real credentials, so we treat security as a product feature, not a page of promises. Here's how ApiSpi protects your keys, your data, and your users โ and how you can verify it.
Connector tokens, OAuth secrets, and provider keys are stored encrypted and never serialised into pages or logs. Secret fields are write-only in every admin screen.
HTTPS enforced with HSTS, plus a strict Content-Security-Policy, frame, MIME, referrer, and permissions headers on every response.
Input and output guardrails, prompt-injection screening, content moderation, blocked-keyword redaction, and policy-as-code rules โ enforced on chat, gateway, MCP, and A2A alike.
Per-tool disable switches, read-only and approval modes for state-changing actions, connector kill switches, and an organisation-wide emergency stop.
Every significant action lands in the activity log with actor attribution; governance events export to CSV or stream HMAC-signed to your SIEM in real time.
Two-factor authentication with recovery codes, Google and Microsoft single sign-on, scoped API keys you can rotate at any time, and admin-only surfaces behind role checks.
We take reports seriously and respond fast. If you believe you've found a security issue in ApiSpi, please contact us with the details โ we'll acknowledge receipt and keep you updated through the fix.
We'll walk your security reviewers through the stack, control by control