AI workflow guides Your workspace
Find your way forward

Security in Superagento

Learn to build AI agents, connect tools and
understand every workflow run.

Reference/Security1 min read

Security

What we do with the keys you give us.

  • Provider keys are held server-side, never sent to the browser and never printed into a run log.
  • Sessions are HttpOnly cookies. Workflow, execution and usage data is scoped to the owning account by the backend, not by the interface.
  • Outbound HTTP steps run behind an allowlist that blocks requests to internal addresses.
A little help goes a long way.Your run history is a good place to find what happened at every step.
Take a closer look