1EOne Engineer

Security at One Engineer

One Engineer operates across your real systems, so safety is the default — not an afterthought. Here is how we protect your code, credentials, and infrastructure.

Read-only by default

Every connector starts read-only. The agent can investigate — read code, inspect Kubernetes, search logs, review pipelines — without the ability to change anything.

Every write is approval-gated

Any mutating action — a commit, a merge request, a rollout restart, a ticket transition — is classified as requiring approval and pauses for an explicit human decision. Nothing changes in your systems without you clicking approve.

Encrypted secrets, scoped per organization

Connection tokens and keys are encrypted at rest. They are scoped to your organization and are never shared across tenants and never used to train models.

Tenant isolation

The platform is multi-tenant by design. Every organization's data — conversations, connections, usage, and billing — is isolated. Member requests derive their organization from a signed session, never from client input, which prevents cross-tenant access.

Auditing & access control

Actions are recorded to an append-only audit log. Role-based access control governs who can read versus change systems, and organization OIDC SSO is available on Team and Enterprise plans. SAML IdPs connect through an external OIDC broker.

Your data

Your code, logs, and prompts are used to answer your requests — not to train models. See our Privacy Policy for details on data handling and retention.

Security questions or want our security overview for a review? Contact us at [email protected].