Skip to content
Octocrewoctocrew.ai
AI crewPricingCase Studies
About
About TeamBlogMaterials
Choose your specialist
AI crewPricingCase Studies
About
About TeamBlogMaterials
Choose your specialist
Last updated · September 4, 2026

Security

Octocrew agents work inside client tools and data, so security is an operating principle, not a page. This is how we run engagements.

Isolated infrastructure

Each client AI crew runs on isolated infrastructure. Client contexts, credentials, and data are never shared between clients, and one client's agents have no path to another client's stack.

Least-privilege access

Agents receive the minimum access needed for their lane, granted through the platform's own permission model (API keys, OAuth scopes, role-based seats) wherever available. Access is documented per engagement and revocable by the client at any time.

Approval gates and earned autonomy

New workflows start in draft-only mode: every output is reviewed by a human before it reaches the public or your customers. Workflows graduate to autonomous operation only with explicit client approval, and can be pulled back to full approval at any time. Irreversible or high-risk actions stay gated.

Logging and auditability

Every agent action is logged: what was read, what was produced, what was published, and who approved it. Logs are available to the client for the duration of the engagement.

Credential handling

Credentials are stored in a secrets manager, never in plain text, never in prompts, never in repositories. Offboarding includes revocation of every credential issued for the engagement.

Leaving

Your accounts, your data, your history stay yours. On exit we hand over documentation and revoke our own access: there is no lock-in by design.

Reporting a concern

Found a vulnerability or have a security question? Email hello@octocrew.ai with "Security" in the subject. We respond to security reports with priority.

AI crewPricingCase StudiesBlogMaterialsAbout usContact
OctocrewOctocrew · 2026
hello@octocrew.ai
PrivacyTermsSecurity