SHADOWOPS // SECURITY & SUBPROCESSORS
Security & Subprocessors
ShadowOps is designed to handle automation data, provider credentials, and user content with layered technical and operational safeguards. No service can guarantee absolute security.
1. Security practices
- Encrypted connections for web and service traffic where supported.
- Password hashing and session protections for account authentication.
- Application-level encryption for stored provider secrets where supported by the deployment.
- Role-based access controls, CSRF defenses, request limits, security headers, and isolation between users and workloads.
- Monitoring, logging, backups, dependency maintenance, and incident response processes appropriate to the service.
Security controls and infrastructure may differ between private preview, development, hosted, and enterprise deployments. Do not place production secrets or regulated data in a preview environment unless your agreement and configuration authorize it.
2. Customer responsibilities
Use strong credentials, protect API keys and OAuth sessions, grant agents only the permissions they need, review tool calls and outputs, keep endpoint software updated, and notify us promptly about suspected compromise. You are responsible for the security of third-party accounts and controllers that you connect.
3. Subprocessors and third-party services
The services below describe the categories of providers ShadowOps may use. The actual set depends on deployment, feature, and account configuration. We will update this list when production providers are finalized.
| Category | Purpose | When involved |
|---|---|---|
| Infrastructure and database providers | Run the application and store account, workflow, and content data | When the hosted service is used |
| Cloudflare or equivalent edge/tunnel provider | Traffic routing, TLS, tunnel connectivity, and abuse protection | When the public hosted endpoint is used |
| Stripe and PayPal | Checkout, subscription management, payments, and billing events | When a payment method is enabled or selected |
| Google and GitHub | OAuth authentication and account linking | When you choose that sign-in method |
| AI and model providers | Inference, embeddings, or other model operations | When selected or required by an agent configuration |
4. Incident reporting
Report suspected security vulnerabilities or unauthorized access to [email protected]. Please provide enough detail to reproduce the issue and avoid including live credentials or private customer data.
5. Enterprise requests
For a security questionnaire, data-processing agreement, subprocessors list, or deployment-specific controls, contact [email protected].