Security & trust

Security at ACP

The default posture of the platform, what we harden by default, and what to expect when something goes wrong.

Last updatedSeptember 27, 2026

Workflow worktrees

Feature and standalone ticket workflows use git worktrees to separate changes. Other workflows can use the project checkout. A worktree is a git workspace, not an operating-system security sandbox.

Encrypted at rest

Connected provider credentials and GitHub App credentials are stored in the credential vault using AES-256-GCM encryption. Free Solo does not require a personal provider key.

Account access

Signed, HTTP-only session cookies protect signed-in access. Project and account permissions are checked by the application when users request protected actions.

Run history

ACP records ticket state, workflow transitions, and run output so you can inspect how work progressed. This history does not capture every file read or command as a separate audit event.

Platform-funded by default

Free Solo agents run on the platform wallet. You do not need to paste a personal provider API key. Optional connected credentials are encrypted in the credential vault.

Incident disclosure

We commit to notifying customers of material security incidents within 72 hours of confirmation. Report a suspected incident to admin@agentcontrolpanel.dev.

Architecture overview

ACP has a web client, server API, persistent application data, and agent execution workflows. The server checks account and project access for protected actions.

Agents can execute tools against a project checkout or a git worktree, depending on the workflow. Review the commands and credentials available to an agent before connecting a repository. Worktree separation alone does not prevent filesystem or network access outside that directory.

Secrets

How we handle your API keys

Free Solo does not collect a personal provider API key. Agents run on the platform wallet. The rest of this section applies only if an administrator later connects a key.

Connected provider credentials are encrypted by the credential vault with AES-256-GCM before storage. GitHub App credentials can also be stored encrypted in that vault.

ACP uses a connected provider key to dispatch the agent requests you authorize. Access to the key is mediated by the server and the credential vault.

You can manage connected provider credentials from Settings → Providers after sign-in.

What an agent can and cannot do

Agent capabilities depend on the configured workflow and tools:

  • Can read and modify project files made available to its execution environment.
  • Can invoke the configured AI provider with project-scoped context.
  • Can run tools and make changes in a project checkout or worktree.
  • Can push a branch and open a pull request when the configured workflow uses GitHub delivery.
  • May have filesystem and network access beyond a worktree unless restricted by the execution environment you configure. Treat connected repositories and credentials as access granted to an agent.

Data residency and retention

ACP does not currently offer a region selector in the public signup flow. Operational logs (access logs and error reports) are retained for up to 90 days and then aggregated or deleted.

On account deletion, we erase workspace data within 30 days, except where law requires longer retention. Backups follow a 35-day rolling window; the last backup of your data is purged at the end of that window.

Compliance and audits

We describe the controls implemented in the product above. For current security documentation or vendor questionnaires, contact our team.

Send security evidence requests to admin@agentcontrolpanel.dev.

Security reports

Responsible disclosure

Found a vulnerability? Please report it responsibly. Do not test against other customers' data or environments.

Email admin@agentcontrolpanel.dev with reproduction steps and a proof of concept if you have one.

Contact

For security questions, audits, or vendor questionnaires, email admin@agentcontrolpanel.dev.