Skip to content
AgentHub

Security & Data

Clear records require clear boundaries.

AgentHub keeps client change records inside a workspace and gives clients narrow, time-limited links for specific decisions. This page explains what those controls do and what they do not prove.

Access stays tied to the record and the decision.

The product uses workspace access controls for operators and purpose-built links for clients.

Workspace access

Signed-in users work inside workspace-scoped records. Database policies and ownership checks restrict access to the active workspace.

Secure approval links

Approval links expire after 14 days, can be revoked or replaced, and accept one client response. AgentHub creates the link. It does not send it automatically.

Human control

AgentHub does not automatically approve, implement, verify, publish, send, or edit a client automation. Those decisions remain with the people responsible for the work.

No-account approval

A secure link is a credential, not an identity claim.

The link lets its holder review one frozen request and respond once. AgentHub records the named response, but the link itself is not an electronic signature or proof of the viewer's identity.

Credential handling

The secret stays in the URL fragment. AgentHub stores only its SHA-256 hash, not the raw token.

Opening the link

The record can show when the approval page was first opened successfully. It does not identify who opened it and does not store an IP address, user agent, or open count for that event.

Approval-page privacy

The approval page is configured as no-index, no-store, and no-referrer, and it does not load third-party analytics.

Invalid links

Expired, revoked, replaced, and invalid links do not disclose the client, workspace, or requested scope.

Record enough to support the decision.

AgentHub is built to hold the operating record around client work, not the secrets that make the automation run.

  • Workflow snapshots exclude credentials, node parameters, field values, and execution payloads.
  • Implementation evidence stores a link and reference. AgentHub does not ingest the linked source code.
  • Approval records preserve the decision while keeping missing identity evidence visible.

Claim discipline

These are product boundaries, not a certification.

This page is not a SOC 2, ISO, privacy-law, or industry-compliance attestation. It describes current AgentHub behavior and will be updated as the product changes.

Last reviewedAugust 15, 2026Report a concern