Security at SteelEngine

Security for the systems your agents touch.

SteelEngine is built to help teams automate consequential work without giving up control. We combine independent assurance, scoped access, protected credentials, and observable execution to reduce risk across the workflow lifecycle.

SOC 2 Type II

Independent assurance

SSO and SCIM

Centralized identity

Scoped authorization

Policy-based access

Our approach

Controls across the product lifecycle

Security is a system of overlapping controls. These are the practices customers encounter most directly when they build, run, and govern work in SteelEngine.

Identity and access

Policy-based access controls apply across the dashboard, APIs, realtime collaboration, and platform MCP. Permissions can be scoped to organizations and workspaces, with SSO and SCIM available for enterprise teams.

Credentials and secrets

Application-managed credentials and bring-your-own-key values are encrypted before storage. Access to use or manage a credential is authorized separately from access to the workflow that references it.

Data boundaries

Customer resources are separated by organization and workspace boundaries. Connected services are accessed only when enabled, using the permissions granted for the requested feature.

Platform safeguards

Hosted traffic is protected in transit with HTTPS. Input validation, scoped API keys, rate limiting, and sensitive-value filtering add defense in depth around exposed product surfaces.

Visibility and accountability

Execution traces help teams understand workflow behavior, while enterprise audit logs record security-relevant actions. Public service health is available on our status page.

Secure delivery

Changes pass automated linting, type checks, unit tests, and integration tests before release. Security reports follow a documented responsible-disclosure process.

Customer data and AI

Your data is used for your work—not generalized model training.

SteelEngine processes data to deliver the workflows, integrations, and features a customer enables. Our Privacy Policy explains what we collect, why we process it, and the controls available to customers and users.

Read our Privacy Policy
  • We process customer data to provide and support the features customers choose to use.
  • Google API data is not used to train generalized AI or machine-learning models.
  • Customers control which integrations, credentials, models, and collaborators they connect.
  • Data access, export, deletion, and retention practices are described in our Privacy Policy.

Security questions

Need documentation or found a vulnerability?

Review our public trust center for assurance materials. To report a potential vulnerability, email our security team and follow the responsible-disclosure guidelines in our Privacy Policy.

security@steelengine.com

Last reviewed August 3, 2026. This page summarizes our practices and does not replace our contractual terms or Privacy Policy.