Security overview
Summary for CISO and procurement reviewers. A PDF export is available on Enterprise request — this page is the canonical text.
Architecture
Secrets encrypt on the user device (libsodium secretbox). The CLI and optional local daemon perform approve/deny before injection into child processes or MCP tools. The web app provides billing, licence delivery, and a preview workspace — it does not receive vault plaintext.
Controls (today)
- Human approve gate for agent and MCP secret requests
- Project allowlists via .latchkey.toml
- Append-only audit metadata (no secret values)
- Ed25519-signed licence verification offline in CLI
- Hosted auth and payments via Supabase and Stripe (see sub-processors)
Roadmap (honest)
- Agent sandbox — isolated tool execution (M22, in design)
- SAML SSO for Business / Enterprise (E2)
- SOC 2 Type I (see SOC 2 status page)
PDF / questionnaire
Email Yusuf@yusuf-choudhury.com with “Security overview PDF” or attach your vendor questionnaire — we respond from the Enterprise queue.