Security and trust

m8tes runs autonomous agents against your real business data. Here is how we protect it.

SOC 2 Type II: on our roadmap

We do not claim SOC 2 certification today. For our security posture, a questionnaire, or a Data Processing Agreement, email privacy@m8tes.ai.

How we protect your data

Encryption

Encrypted in transit, credentials at rest

All traffic is encrypted in transit. Integration credentials and OAuth tokens are encrypted at rest.

Isolation

Every run is sandboxed

Each run executes in its own isolated, ephemeral sandbox. Credentials never reach the subprocesses that read your data.

Access

Strong authentication

Optional two-factor authentication, revocable sessions, rate-limited sign-in, and an audit trail of every account change.

Your data

We never train on your data

Your content and outputs are never used to train AI models — by us or our subprocessors. Request a copy or deletion any time.

Data retention

Optional zero data retention

Switch an account to zero-data-retention mode and conversations, tool output, and reports are never stored, only run metadata. Most models also run on providers that retain no content; the few without a zero-data-retention host are flagged in the API model list and in the data retention docs.

Multi-tenancy

Strict per-tenant isolation

Serving your own end-users? Each end-user's data is strictly isolated, with per-user run and spend caps.

Infrastructure

Certified providers

Core infrastructure runs on certified providers: DigitalOcean (SOC 2), Anthropic (SOC 2), and Stripe (PCI DSS).

Subprocessors

The third parties that may process your data to provide the service. Optional channels only apply if you enable them.

SubprocessorPurposeData processedLocation
AnthropicLLM inference (Claude)Task instructions, messages, and context you send to a MateUnited States
DaytonaSandbox compute for agent runsRun code, uploaded files, and tool input/output during executionUnited States
DigitalOceanCloud hosting and databaseAll platform data stored at restUnited States
StripePayments and billingBilling contact and tokenized payment method (we never store card numbers)United States
ResendTransactional email deliveryRecipient email address and notification contentUnited States
ComposioThird-party integration brokerageConnection metadata and OAuth tokens for apps you connectUnited States
OpenAITask title generationA brief excerpt of your message and the agent's response, to generate a task titleUnited States
SlackInbound and outbound messaging (optional)Message content, sender identity, and workspace identifiers, only if you connect SlackUnited States
PostHogProduct analyticsBrowser page views and your email after you accept analytics cookies; plus pseudonymous server-side product/usage events keyed to an account ID with operational metadata (sign-in method, plan, resource IDs), never email or nameUnited States
SentryError monitoringError traces and request metadata (redacted of secrets)United States
GoogleOAuth sign-in and connected APIsAccount identifiers and the data you authorize (e.g. Google Ads)United States
TwilioSMS and phone numbers (optional)Phone number and message content, only if you enable SMSUnited States
BlueBubblesiMessage bridge (optional, self-hosted)iMessage content routed through a bridge you host and controlSelf-hosted by you
Cal.comDemo schedulingName and email you submit when booking a demoUnited States
ApolloWebsite visitor analyticsSite visit data (only after you accept analytics cookies), which may be matched to business contact information Apollo holdsUnited States

What's next

Ask about timelines if any of these are a requirement for your team.

  • SSO / SAML and SCIM provisioning
  • Customer-facing audit-log dashboard
  • SOC 2 Type II report

Responsible disclosure

Found a security issue in m8tes.ai, api.m8tes.ai, or our SDK? Report it privately with steps to reproduce — we acknowledge within 48 hours and aim to fix critical issues within 14 days. Third-party services we integrate with are out of scope; report those to the vendor. Email support@m8tes.ai.

Safe harbor

We will not pursue legal action against good-faith research. Test only accounts and data you own, avoid privacy violations and any destruction or exfiltration of data, do not degrade the service for others, and give us time to fix an issue before disclosing it publicly. When in doubt, ask us first.

For data, privacy, or DPA requests, contact privacy@m8tes.ai. See our Privacy Policy and Terms.