Skip to main content

Your organization is isolated

Every agent, key, connection, configuration entry and log belongs to one organization, and every request is checked against it. An agent in another organization answers 404, exactly as one that does not exist, so nobody can learn what exists outside their own organization. Each agent runs in its own isolated runtime, and each session in its own instance.

API keys

  • A key is shown once, when it is created. Onecortex stores only a SHA-256 hash of it, so it cannot be shown again or recovered, by you or anyone at Onecortex.
  • A key can only invoke agents. It cannot create, change, deploy or delete anything, or read configuration or logs.
  • A key can be scoped to one agent, given an expiry, and revoked. A revoked key stops working within 30 seconds.
  • Every rejected key gets the same answer, so a caller cannot tell a revoked key from a mistyped one.
See API keys.

Secrets

  • Secret values go straight to encrypted storage. They are never written to Onecortex’s database, its logs or its build records, and nothing in Onecortex can read one back to show you.
  • They are given to your agent when a version is released, as environment variables.
  • They are not available to your build, and the smoke test runs with placeholders, never the real values.
See Configuration and secrets.

Your code

  • The Onecortex GitHub app asks for read only access to repository contents and metadata, and your email address. It has no write permission of any kind: it cannot commit, open a pull request, or change a setting.
  • Your source is never modified. The build adds its own files beside your code, in the build only.
  • Your code is built into an image that only your agent runs.

Your calls

  • The endpoint is HTTPS only, with HSTS.
  • Onecortex logs a call’s sizes, duration and outcome, never its prompt, its reply, or its tool arguments and results, in its own records. Your agent’s own logs capture inputs and outputs unless you turn that off.
  • An error from inside the platform never reaches the caller as it is: the caller gets a code, a plain message and a request ID.
  • Your session IDs never reach the infrastructure as you sent them: Onecortex derives an internal identifier from them.

Report a vulnerability

Email [email protected].
Last modified on September 28, 2026