security

your agents run with your credentials, your data, and your integrations.
we treat that responsibility seriously.

how we protect your data

encrypted everywhere

all data encrypted in transit (TLS 1.2+) and at rest (AES-256). secrets use envelope encryption with key rotation.

isolated execution

agents run in sandboxed containers. minimal base images, non-root processes, no shared state between tenants.

audited access

every authentication, authorization, and data access event is logged. alerts fire on suspicious patterns automatically.

enterprise SSO

SAML 2.0 single sign-on. your identity provider controls who has access. one login across all inference shell surfaces.

no training on your data

your inputs and outputs are yours. we don't use customer content to train models or share it with third parties.

compliance

compliantGDPRcompliant
compliantPCI DSScompliant
compliantHIPAABAA available
in progressSOC 2in progress*
in progressISO 27001in progress*

reporting a vulnerability

if you've found a security vulnerability in inference shell or belt.sh, we want to hear about it.

email: [email protected]

please include:

  • description of the vulnerability
  • steps to reproduce
  • affected component (api, cli, web, skills, agents)
  • impact assessment (what an attacker could do)

we will acknowledge your report within 48 hours and aim to provide a fix timeline within 5 business days.

reporting abuse

for abuse reports (malicious skills, apps, or agents): [email protected]

for dmca takedown requests: [email protected]

what we protect

  • all skill content is scanned by our security scanner (INF-SEC rules) before serving
  • credentials detected in skill content or agent output are automatically redacted
  • hook tool URLs are validated (https required, no localhost)
  • critical security findings block skill publishing automatically

scope

in scope:

  • inference shell api and web application
  • belt.sh web application and belt cli
  • skill store and registry
  • agent runtime and execution
  • mcp connector proxy
  • authentication and authorization

out of scope:

  • third-party app provider vulnerabilities (report to the provider directly)
  • social engineering attacks
  • denial of service attacks
  • issues in dependencies already reported upstream

disclosure policy

  • we follow coordinated disclosure - please give us reasonable time to fix before publishing
  • we will not pursue legal action against researchers acting in good faith
  • we credit researchers in our changelog (unless you prefer anonymity)

policies

  • information security policy
  • incident response policy
  • data classification policy
  • vendor management policy
  • business continuity policy
  • change management policy

full policy documents are available under NDA for enterprise evaluations and compliance reviews. contact [email protected] to request access.

machine-readable security contact: /.well-known/security.txt

ready to ship?

start with the hosted platform. deploy your own when you're ready.

we use cookies

we use cookies to ensure you get the best experience on our website. for more information on how we use cookies, please see our cookie policy.

by clicking "accept", you agree to our use of cookies.
learn more.