[00]Security
Safe by construction. Visible by default.
Agents in Dispatch read, search and draft on their own, but nothing leaves the board without a person. Here is how the product keeps your workspace separate, your secrets sealed and every action on the record.
- 01RequestBrowser, API key or webhook
- 02Session & roleSigned session, workspace role checked on the server
- 03ValidationEvery body, query and param parsed by a schema
- 04Workspace scopeEach query filtered by your workspace id
- 05Your dataTenant rows, private files, encrypted secrets
[01]Practices
What protects your work.
The controls below are part of the product itself, on every plan, and they apply to people and agents alike.
Tenant isolation
Every query is scoped by workspace in the data-access layer. Ids sent by the browser are re-checked against your workspace before anything is read or written.
Encrypted secrets
Integration tokens and custom tool headers are encrypted at rest with AES-256-GCM, in a versioned format that allows key rotation. Traffic is served over TLS.
Approval for every side effect
Sending an email, posting to Slack, writing to Notion or Drive, or calling a webhook pauses the run and shows the exact payload. Approvals, edits and rejections are audited.
Untrusted content stays data
Fetched pages and uploaded files are treated as data, never as instructions. Private-network and localhost addresses are blocked, robots.txt is respected and sizes are capped.
Private files
Uploads live in a private bucket. Downloads go through signed links that expire after five minutes, issued only after your access is checked.
Access control
Owner, admin, member and viewer roles are enforced on the server. Sessions can be listed and revoked; API keys are hashed, scoped and rate limited.
Audit trail
Admin actions, approvals, tool executions and support impersonation are logged with who acted, when, and what changed.
Signed webhooks
Outbound webhook payloads are signed with HMAC-SHA256 and retried with backoff. Every delivery and response code is kept in a log.
Limits and abuse controls
Sign-in, the API and run creation are rate limited. Each run has a token budget and a time limit; demo sessions have a run budget and expire after 30 minutes.
[02]Privacy & GDPR
Your data stays yours.
- No training on your data. Inputs, files and artifacts are used only to run your cards.
- Export at any time. Download your data as JSON from account settings, and export any artifact as Markdown, CSV or JSON.
- Delete for real. Deleting a workspace starts a 7-day grace period, then removes it with its files. Deleting your account removes your personal data.
- Consent on the record. Every acceptance of the terms, privacy and cookie choices is stored with the exact text shown, and you can review it.
- EU hosting option. Workspaces can be hosted in the EU; subprocessors are listed publicly.
Found a vulnerability?
Write to us before telling anyone else. We reply within two business days, keep you informed while we fix it, and credit you if you wish. Please do not test against other people’s workspaces.
See the safeguards before you trust them.
Run a card in the demo, watch every step in the trace, and approve or reject the email it wants to send.