1EOne Engineer

Security at One Engineer

Last updated: August 4, 2026.

One Engineer operates across your real systems, so safety is the default — not an afterthought. Here is how we protect your code, credentials, and infrastructure.

Read-only by default

Every connector starts read-only. The agent can investigate — read code, inspect Kubernetes, search logs, review pipelines — without the ability to change anything.

Writes are policy-gated

Any mutating action — a commit, a merge request, a rollout restart, a ticket transition — is classified before execution. Writes require explicit human approval by default. An authorized organization administrator may allow narrowly scoped autonomous actions for eligible, non-protected targets; protected or forbidden actions cannot use that allowance. Approval requests include the proposed action and target, and stale or changed approvals are revalidated before execution. Every attempted action is recorded in the organization audit trail.

Production approvals are one-time, tied to the authenticated approver and organization role, and expire after 15 minutes unless a shorter validity period is shown. We recheck the target, connection, policy, credits, permissions, and approval fingerprint immediately before dispatch. If the target changes or the approval expires, the system requests a fresh approval instead of replaying the old one.

Encrypted secrets, scoped per organization

Connection tokens and keys are encrypted at rest. They are scoped to your organization and are never shared across tenants and never used to train models. Application traffic uses TLS in transit, and stored secret material is separated from ordinary configuration wherever possible.

Tenant isolation

The platform is multi-tenant by design. Every organization's data — conversations, connections, usage, and billing — is isolated. Member requests derive their organization from a signed session, never from client input, which prevents cross-tenant access.

Auditing & access control

Actions are recorded to an append-only audit log. Role-based access control governs who can read versus change systems, and organization OIDC SSO is available on Team and Enterprise plans. SAML IdPs connect through an external OIDC broker. Administrators can approve only actions permitted by their current organization role and connection permissions.

Sandboxed execution

Workspace commands run in isolated worker sandboxes instead of the public web process. Production sandboxes run with non-root users, dropped Linux capabilities, bounded CPU and memory, read-only root filesystems, network controls, workspace path isolation, and explicit deadlines.

Incident response and breach notification

We monitor service health, audit sensitive actions, and investigate suspected abuse or security events. If we determine that a security incident affects customer data, we will notify impacted organization owners or security contacts without undue delay and, where legally required, within 72 hours after confirmation. We provide known impact, affected data categories, mitigation steps, recommended customer actions, and follow-up contacts when available, with reasonable updates as the investigation progresses.

Backups, retention, and recovery

We use backups and operational retention controls to support reliability and recovery. Current production database backups are retained on a rolling 30-day schedule. Task data, artifacts, workspace outputs, and audit records follow the retention periods described in our Privacy Policy. Backup restoration is tested through controlled recovery drills; public self-service plans do not include a contractual RTO or RPO unless a separate agreement says otherwise.

Availability and support

The public Service is monitored for health and readiness, and we prioritize incidents based on customer impact and security risk. Public self-service plans do not include a formal uptime SLA or guaranteed support response time. Enterprise customers may request negotiated support, SLA, recovery, and incident cooperation terms.

Your data

Your code, logs, and prompts are used to answer your requests — not to train models. See our Privacy Policy for details on data handling and retention.

Security reviews

Customers evaluating One Engineer for sensitive environments may request additional security documentation, subprocessor information, and enterprise data-processing terms.

Security questions or want our security overview for a review? Contact us at [email protected].