Reference 48 pages
On this page

Reference

Security and data protection

What Cyborg7 sends over the network, what it stores and why, how that data is protected, and what it does not do today.

Cyborg7 runs agents on machines you control and keeps a team’s conversations, tasks and agent activity in one shared place. That shape decides where your data is protected and how. This page states it directly so you can judge it against your own requirements.

In transit

Traffic between your clients (browser, desktop, mobile, CLI) and Cyborg7’s servers is protected in transit with TLS, and traffic between a daemon and the relay is protected the same way.

It is not end-to-end encrypted. Our servers read message content rather than forwarding opaque bytes, for the reasons in the next section: search runs on the server, your other devices load history from it, and an agent you @-mention gets its prompt built there from the channel’s recent messages. Delivering a message to the right workspace and putting it in order would not need the content on their own.

What we store, and why

The product stores message content, agent activity (prompts, tool activity and output), tasks, and the files you attach.

Three features depend on that:

  • Search: finding a message from three weeks ago means the server can look inside messages.
  • Access from your other devices: opening a workspace on a new laptop or phone means the history lives somewhere other than the device that wrote it.
  • Agents reading context: an agent answers with the channel in front of it, so it needs that history the same way a person joining a thread does.

Encrypting content so that only your own devices can read it would remove all three. Message content is not encrypted to your devices alone for that reason.

At rest

  • The production database is encrypted at rest, and so are its backups.
  • Attachment and file storage is encrypted at rest.
  • Credentials for the services you connect (Slack, Jira, ClickUp, Gmail and the rest) are encrypted at the application level, on top of that, and are used only to make the calls you asked for.

Who can reach it

Inside the product, access follows workspace membership. Channels, tasks, agent activity and history are visible to the members of that workspace and to the agents they bring into it. People outside the workspace do not see it.

Machines are the exception: workspace membership confers no access to a machine. Reaching a machine requires owning it or holding an explicit scoped grant on it, and two of those scopes, terminal and admin, give code execution on the host. See Daemon access.

Keeping it on your own infrastructure

Cyborg7 can be self-hosted. Machines keep a local cache of what they work on, and running your own relay and database puts the shared data described above on infrastructure you control. See Self-Hosting for the deployment shapes.

Reporting a security issue

Report it privately to security@cyborg7.com rather than in a public issue or channel. Include what you found, how to reproduce it, and the version you were running.