Third Party Index

Snapshot 48392

Document
Security page
URL
https://www.activepieces.com/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
92770 bytes
SHA-256 (raw)
ab3643d96e3e6bc8e835f348381d34c689bcbd002393997cad9fd153cc701333
SHA-256 (normalized text)
596aafc41ed0193e907e974450fc1a350d4db6ad97324dee3173fabc00225d30

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to content
Serious security for serious agents.
An agent can work in production without ever holding a credential. Everything it does is on the record, and the whole platform can run inside your own network.
Open the trust center Read the source
EU hosted
Our cloud runs in Frankfurt by default
SOC 2 Type 2
Independently audited and penetration tested
AES-256 encrypted
Encryption in transit and at rest, everywhere
No model training
Your runs and documents are never training data
Choose where it runs
Our cloud, hosted in the EUFrankfurt by default, other regions on request. Each project keeps its own automations, connections and history.
Or inside your own networkThe same enterprise build, in whatever region your policy asks for, on hardware nobody else shares.
Or air-gapped, with no internetNothing reaches out of your network, and the model answering your agents runs on your own machines.
No one can read a credential
Never shown again after savingNot through the API, not in the builder, not in an export. The worker unlocks the secret only while a step runs.
Agents never see the secretAn agent picks a connection by name, so the secret behind it never reaches a prompt or a model.
Or store them in your own vaultVault, AWS Secrets Manager, CyberArk Conjur and 1Password can pass the value in at run time, so we never store it.
Runs are isolated and audited
Each run gets its own sandboxHardened mode runs the engine in an isolate, with a filesystem view and caches of its own.
You decide what a run can reachThe engine checks every outbound request, and your network boundary decides what actually leaves.
Big actions wait for approvalAn agent reaches only the tools you gave it, and every action it takes is recorded as it happens.
Adopt with confidence
What we keep
Your automations, runs, files, documents and connections, kept only as long as you choose.
Always encrypted
AES-256 on disk and TLS on the wire, with every credential encrypted as its own value.
Never training data
Your automations, runs, documents and prompts never train a model, ours or anyone else's.
A full audit trail
Every action is recorded, by a person or a model, and the trail can stream to your SIEM.
Export it all
Automations are plain JSON and export through the API, with your tables, files and runs.
Outside auditors
SOC 2 Type 2 and a penetration test from early 2026, with the reports in the trust center.
Where a review usually starts
Our cloud runs in Frankfurt by default, and we can host elsewhere if your policy needs it, so ask. Self-hosted, the same enterprise build runs on your own infrastructure in any region you choose, on hardware nobody else shares.
Yes. An air-gapped deployment keeps everything inside your network and runs your own model on your own hardware. Short of that, inference can point at any OpenAI-compatible endpoint you operate.
No. An agent references a connection by name and the platform resolves it inside the worker as the step runs. The value is never returned by the API, never shown back in the interface, and never included in an export.
No. Your automations, runs, documents and prompts are never training data. Model input and output are stored in run history like any other step, under the retention window you set.
Yes. Questionnaires and vendor reviews go through our team. The current SOC 2 Type 2 documents are in the trust center if that answers the question sooner.
Automations are plain JSON and export through the API, along with your tables, files and run history. The core is MIT licensed, so you can keep running the same automations on your own infrastructure.