Cyborg Systems, Corp.

Security

Agents with real power need real guardrails. Here is how Cyborg is built, what we protect, and what you control.

Last updated October 2, 2026

1. Architecture

Cyborg splits the work between the machines you connect and our cloud.

  • Agents run where you choose. The Cyborg software starts agents, terminals and sessions on the computers you connect: a laptop, a dedicated workspace machine or a cloud server. Your files stay on those computers unless an agent sends them somewhere at your direction.
  • Subscriptions or API keys. Agents use your own AI subscriptions or API keys. Keys you add are stored on the machine running your agents, in a file encrypted with AES-256-GCM and readable only by its user account, and the software strips provider keys from the processes it starts.
  • Your code stays on your machines. Repositories live on the computers where your agents run. Cyborg cloud does not clone, index or store your codebase.
  • Our cloud syncs the workspace. Cyborg cloud relays and stores workspace data: messages, tasks, files and recent agent history. Terminal output streams through it in real time and is never stored.

2. Data protection

  • In transit: all connections to Cyborg cloud use TLS.
  • At rest: our database runs on Amazon RDS, encrypted with AWS KMS. Uploaded files are stored encrypted in Amazon S3 and served through short-lived signed URLs.
  • Credentials: access tokens for Slack, Microsoft Teams, GitHub, Jira, Linear and ClickUp are encrypted at the application layer with AES-256-GCM. Passwords are stored only as scrypt hashes, and we support passkeys.
  • Secrets in conversations: when a message or an agent transcript contains something that looks like a credential, we detect it and seal it with an encryption key specific to your workspace, wrapped by AWS KMS.
  • Backups: automated, encrypted, and kept for 14 days. The production database is not publicly reachable, runs across multiple availability zones and has deletion protection enabled.
  • No training: we do not train AI models on your content, and neither do our subprocessors.

3. Controls in the product

  • Roles: owner, admin, member and viewer, with permissions checked on every action.
  • Machine access: access to each machine is granted separately for chatting with agents, running agents, using terminals and administering the machine. The machine’s owner decides.
  • Workspace machines: only admins who own a machine can make it a workspace machine, and they choose what members may do on it.
  • Agent permissions: each agent gets only the tools you grant it, and can be required to ask for approval in the channel before it acts. Approvals are signed and tied to the person who asked.
  • Browser guardrails: agents that browse are blocked from local network and cloud metadata addresses, and can be limited to the sites and actions you allow.
  • Audit logs: sign-ins, administrative changes and billing actions are recorded.
  • Sessions: sign-in attempts are rate-limited, sign-in codes are verified by email, and sessions and machine tokens can be revoked.

4. Infrastructure and engineering

  • Cyborg cloud is hosted on Amazon Web Services in the United States, behind a load balancer with a web application firewall.
  • Every change ships through a pull request that must pass automated checks, including secret scanning and dedicated security test suites for the server and the database.
  • Access to production systems is limited to a small number of engineers.
  • Logs and diagnostics are scrubbed of detected secrets before they leave our systems, and product analytics never include message, prompt or response content.

5. Shared responsibility

Security with agents is a partnership. We secure the platform. You decide what your agents may do.

Cyborg secures

  • Cyborg cloud and its infrastructure
  • Encryption of data in transit and at rest
  • Access controls and permission checks
  • The Cyborg software and its updates
  • Our subprocessors

You control

  • Which machines you connect and what is on them
  • Each agent’s tools, access and approval settings
  • The credentials and scopes you give agents
  • Who can use your workspace machines
  • Reviewing agent work before it ships
  • Your AI provider account and its settings

Our advice: connect dedicated machines for agents that run around the clock, grant the least access each agent needs, require approval for anything irreversible, and keep backups.

6. Compliance

We are starting our SOC 2 audit process, and we will publish our progress here. Until our report is issued, we are glad to answer your security questionnaire and walk you through our controls: email s@cyborg7.com. Our Privacy Policy and Data Processing Addendum, available on request, cover GDPR and U.S. state privacy law.

Cyborg’s design also limits what there is to protect in the first place. Agents run on machines you control, your code and repositories stay there, and so do your API keys. Our cloud does not clone, index or store your codebase. It syncs the conversation: messages, tasks, files you share and recent agent history, which can include excerpts that agents post.

7. Report a vulnerability

If you think you have found a security issue, email s@cyborg7.com with the details and steps to reproduce. We will acknowledge your report within 5 business days and keep you updated as we fix it.

We will not pursue legal action against research that is done in good faith and follows these rules: test only against your own accounts and workspaces, do not access, modify or keep other people’s data, do not degrade the Service, and give us reasonable time to fix the issue before you disclose it. We do not currently run a paid bug bounty program.