Security and trust
m8tes runs autonomous agents against your real business data. Here is how we protect it.
SOC 2 Type II: on our roadmap
We do not claim SOC 2 certification today. For our security posture, a questionnaire, or a Data Processing Agreement, email privacy@m8tes.ai.
How we protect your data
Encryption
Encrypted in transit, credentials at rest
All traffic is encrypted in transit. Integration credentials and OAuth tokens are encrypted at rest.
Isolation
Every run is sandboxed
Each run executes in its own isolated, ephemeral sandbox. Credentials never reach the subprocesses that read your data.
Access
Strong authentication
Optional two-factor authentication, revocable sessions, rate-limited sign-in, and an audit trail of every account change.
Your data
We never train on your data
Your content and outputs are never used to train AI models — by us or our subprocessors. Request a copy or deletion any time.
Data retention
Optional zero data retention
Switch an account to zero-data-retention mode and conversations, tool output, and reports are never stored, only run metadata. Most models also run on providers that retain no content; the few without a zero-data-retention host are flagged in the API model list and in the data retention docs.
Multi-tenancy
Strict per-tenant isolation
Serving your own end-users? Each end-user's data is strictly isolated, with per-user run and spend caps.
Infrastructure
Certified providers
Core infrastructure runs on certified providers: DigitalOcean (SOC 2), Anthropic (SOC 2), and Stripe (PCI DSS).
Subprocessors
The third parties that may process your data to provide the service. Optional channels only apply if you enable them.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Anthropic | LLM inference (Claude) | Task instructions, messages, and context you send to a Mate | United States |
| Daytona | Sandbox compute for agent runs | Run code, uploaded files, and tool input/output during execution | United States |
| DigitalOcean | Cloud hosting and database | All platform data stored at rest | United States |
| Stripe | Payments and billing | Billing contact and tokenized payment method (we never store card numbers) | United States |
| Resend | Transactional email delivery | Recipient email address and notification content | United States |
| Composio | Third-party integration brokerage | Connection metadata and OAuth tokens for apps you connect | United States |
| OpenAI | Task title generation | A brief excerpt of your message and the agent's response, to generate a task title | United States |
| Slack | Inbound and outbound messaging (optional) | Message content, sender identity, and workspace identifiers, only if you connect Slack | United States |
| PostHog | Product analytics | Browser page views and your email after you accept analytics cookies; plus pseudonymous server-side product/usage events keyed to an account ID with operational metadata (sign-in method, plan, resource IDs), never email or name | United States |
| Sentry | Error monitoring | Error traces and request metadata (redacted of secrets) | United States |
| OAuth sign-in and connected APIs | Account identifiers and the data you authorize (e.g. Google Ads) | United States | |
| Twilio | SMS and phone numbers (optional) | Phone number and message content, only if you enable SMS | United States |
| BlueBubbles | iMessage bridge (optional, self-hosted) | iMessage content routed through a bridge you host and control | Self-hosted by you |
| Cal.com | Demo scheduling | Name and email you submit when booking a demo | United States |
| Apollo | Website visitor analytics | Site visit data (only after you accept analytics cookies), which may be matched to business contact information Apollo holds | United States |
What's next
Ask about timelines if any of these are a requirement for your team.
- SSO / SAML and SCIM provisioning
- Customer-facing audit-log dashboard
- SOC 2 Type II report
Responsible disclosure
Found a security issue in m8tes.ai, api.m8tes.ai, or our SDK? Report it privately with steps to reproduce — we acknowledge within 48 hours and aim to fix critical issues within 14 days. Third-party services we integrate with are out of scope; report those to the vendor. Email support@m8tes.ai.
Safe harbor
We will not pursue legal action against good-faith research. Test only accounts and data you own, avoid privacy violations and any destruction or exfiltration of data, do not degrade the service for others, and give us time to fix an issue before disclosing it publicly. When in doubt, ask us first.
For data, privacy, or DPA requests, contact privacy@m8tes.ai. See our Privacy Policy and Terms.
