SECURITY MODEL

Separate by design.
Specific about trust.

Rootlabs uses tested tenant boundaries and explicit operational controls. We describe what those controls do without pretending any AI service is risk-free.

Dedicated runtime

Each entitled customer runs in a separate whole-process agent container with its own identity and active state directory.

Scoped credentials

Agent runtimes receive scoped model-gateway credentials. Provider master credentials are not placed inside them.

Encrypted secrets

Managed Bot and runtime credentials are encrypted with tenant-scoped key material.

Finite execution

Plan limits and explicit tool, model, time and execution budgets constrain every paid path.

Recovery checkpoints

Health checks, backups, upgrades and restores follow controlled workflows with recorded evidence.

Privacy-aware operations

Central operational telemetry does not collect raw conversation content by default; support diagnostics are redacted.

THE DATA BOUNDARY

What still leaves the runtime.

Messages and instructions needed to produce an answer are sent to the configured model provider. That provider may log or use submitted data under its own terms.

Do not send passwords, API keys, wallet seed phrases, private keys or other secrets. Rootlabs does not need custody of your wallet or provider credentials.

DELETION

Deletion is a verified workflow, not a button-shaped promise.

Starting deletion revokes access and begins removal of the runtime, workspace, credentials and applicable customer-specific recovery data. Rootlabs does not mark deletion complete until the required verification checkpoints pass. Residual provider-side handling remains subject to the provider’s policies.

Ask a security question