Identity and access
Policy-based access controls apply across the dashboard, APIs, realtime collaboration, and platform MCP. Permissions can be scoped to organizations and workspaces, with SSO and SCIM available for enterprise teams.
Security at SteelEngine
SteelEngine is built to help teams automate consequential work without giving up control. We combine independent assurance, scoped access, protected credentials, and observable execution to reduce risk across the workflow lifecycle.
SOC 2 Type II
Independent assurance
SSO and SCIM
Centralized identity
Scoped authorization
Policy-based access
Our approach
Security is a system of overlapping controls. These are the practices customers encounter most directly when they build, run, and govern work in SteelEngine.
Policy-based access controls apply across the dashboard, APIs, realtime collaboration, and platform MCP. Permissions can be scoped to organizations and workspaces, with SSO and SCIM available for enterprise teams.
Application-managed credentials and bring-your-own-key values are encrypted before storage. Access to use or manage a credential is authorized separately from access to the workflow that references it.
Customer resources are separated by organization and workspace boundaries. Connected services are accessed only when enabled, using the permissions granted for the requested feature.
Hosted traffic is protected in transit with HTTPS. Input validation, scoped API keys, rate limiting, and sensitive-value filtering add defense in depth around exposed product surfaces.
Execution traces help teams understand workflow behavior, while enterprise audit logs record security-relevant actions. Public service health is available on our status page.
Changes pass automated linting, type checks, unit tests, and integration tests before release. Security reports follow a documented responsible-disclosure process.
Customer data and AI
SteelEngine processes data to deliver the workflows, integrations, and features a customer enables. Our Privacy Policy explains what we collect, why we process it, and the controls available to customers and users.
Read our Privacy PolicySecurity questions
Review our public trust center for assurance materials. To report a potential vulnerability, email our security team and follow the responsible-disclosure guidelines in our Privacy Policy.
Last reviewed August 3, 2026. This page summarizes our practices and does not replace our contractual terms or Privacy Policy.