Security and control

Access with limits.
Actions with a record.

The controls built into AgentMagic, what they cover and where human oversight still matters.

Accounts and organisation boundaries

AgentMagic uses organisation-scoped application checks and PostgreSQL row-level security for tenant data. Team roles and assistant permissions determine which resources and tools a person can use. This is logical separation on shared infrastructure; it is not a separate server or database for every organisation.

Password sign-in uses salted scrypt hashes. Cloud sessions use HttpOnly, Secure cookies in production and SameSite=Strict. Login endpoints are rate-limited. Registered device credentials are stored as hashes and can be revoked.

Connection credentials

Stored connector credentials and organisation API keys are encrypted with organisation-bound context. Access depends on the active organisation, connection status and tool permissions. Revoking a connection or its provider-side authorisation removes future access through that route.

Provider keys should be entered through the app’s designated settings. Do not paste passwords, session tokens or API keys into ordinary chat or send them to support. Installed CLI providers use their existing login; AgentMagic does not extract or forward their subscription credentials.

Permission and approval checks

The platform checks the requesting person’s role, assistant scope, connected account, concrete resources and applicable policy before a tool runs. External writes require approval by default. Saved approvals cover matching actions within their recorded scope and remain subject to current permissions and limits.

Administrators can revoke saved approvals to restore prompts for future actions. Local desktop approval cannot grant cloud permissions that the user does not hold. Approval does not make an inaccurate draft correct; review the requested action and its consequences.

Audit and usage records

Actions and approval decisions are recorded in an append-only, hash-linked audit trail. This supports investigation and makes certain changes detectable. It does not prevent every attack or provide independent certification against a fully compromised privileged system.

Usage reservations help enforce budgets and avoid duplicate settlement. Uncertain external writes are held for reconciliation rather than blindly retried. Technical support diagnostics use an allowlisted metadata schema that excludes prompt text, argument values, raw provider responses and credentials. Chat, work and audit records are separate records and may contain business information.

Local and cloud choices

The Mac app can use local models. That places the selected model’s inference on your computer; it does not make every connection or account feature offline. Cloud models, connected services, synchronisation and authorised external actions may transfer relevant data to online systems.

Protect the devices you use, keep software updated, restrict administrator access and review model routing. Discuss regulated data, contractual security requirements and deployment constraints with us before connecting sensitive workflows. We do not claim SOC 2, ISO 27001 or other third-party certification on this page.

Report a security issue

Email support@agentmagic.app with the subject “Security report”. Include the affected feature, app version, concise reproduction steps and expected impact. Use the minimum information needed to explain the issue.

Do not access another organisation’s data, disrupt service or publish secrets while investigating. If you encounter private information unexpectedly, stop, preserve only minimal evidence and contact us. We will assess the report and coordinate next steps. This page does not establish a paid bug bounty or a specific response-time guarantee.