Dedicated runtime
Each entitled customer runs in a separate whole-process agent container with its own identity and active state directory.
Scoped credentials
Agent runtimes receive scoped model-gateway credentials. Provider master credentials are not placed inside them.
Encrypted secrets
Managed Bot and runtime credentials are encrypted with tenant-scoped key material.
Finite execution
Plan limits and explicit tool, model, time and execution budgets constrain every paid path.
Recovery checkpoints
Health checks, backups, upgrades and restores follow controlled workflows with recorded evidence.
Privacy-aware operations
Central operational telemetry does not collect raw conversation content by default; support diagnostics are redacted.
What still leaves the runtime.
Messages and instructions needed to produce an answer are sent to the configured model provider. That provider may log or use submitted data under its own terms.
Do not send passwords, API keys, wallet seed phrases, private keys or other secrets. Rootlabs does not need custody of your wallet or provider credentials.
Deletion is a verified workflow, not a button-shaped promise.
Starting deletion revokes access and begins removal of the runtime, workspace, credentials and applicable customer-specific recovery data. Rootlabs does not mark deletion complete until the required verification checkpoints pass. Residual provider-side handling remains subject to the provider’s policies.
Ask a security question