trust ▸ your data, your machine LEGAL

Your data, your accounts, your machine.

Writ automates the sites you already log in to - with your credentials encrypted at rest, injected only at run time, and never returned, shown to AI, or logged.

Encrypted at rest Injected at run time Local runs stay local
Writ runs on your own accounts, with your own credentials and data, on sites you are authorized to use.
crypto ▸ encryption at rest 02

Credentials injected at run time - never exposed

Every sensitive value is encrypted at rest with the platform key and resolves to a real value only inside a single run. Nothing sensitive is ever returned, shown to AI, or logged.

What is encrypted

  • Persona passwords and 2FA (TOTP) seeds
  • Vault secrets, mailbox tokens, magic-link credentials
  • Network egress credentials you supply
  • Saved warm auth sessions (cookies, storage, headers)

How keys and tokens work

  • Secrets are Fernet-encrypted at rest with the platform key
  • Secret references resolve to real values only inside a single run
  • API keys are prefixed wt_
  • OAuth tokens wto_ are Argon2-hashed, scoped, and revocable
Fernet at rest Write-only secrets Argon2-hashed tokens Runtime-only resolution

Never returned. Secrets are never returned through the API, shown to the AI navigation model, or written to logs. The non-secret login identifier is visible so you can tell accounts apart; nothing sensitive is. See the secrets vault and personas.

local ▸ runs on your machine 03

On local runs, your data never leaves your machine

Writ runs on your own hardware by default. Nothing is sent anywhere, your AI keys stay local, and there is no compute charge. Move to the managed cloud only when you want to.

Run on your machine

Pages, extracted data, credentials, and AI keys stay on your device. Reach intranet-only systems, and pay nothing for compute - BYO-AI runs are unbilled.

Or run in the managed cloud

When you need scheduling and scale, the managed cloud fleet runs it, metered by running time from your prepaid balance beyond the included usage.

You choose the venue per workflow. Learn how venues are picked on the agents page.

isolation ▸ tenant boundaries 04

One tenant can never read another's data

Every record is scoped to an organization's tenant ID and filtered at the data layer. Isolation is the default, not a setting you turn on.

Workflows, monitors, personas, secrets, agents, runs, and the wallet are all tenant-scoped and filtered at the data layer. The same boundary governs the marketplace and BYO-agent routing: installs run in your tenant, on your data, and sensitive runs (logins, secrets) are never routed to a foreign machine.

Tenant-scoped at the data layer

Organization Aworkflows · secrets · runs · wallet
Organization Bworkflows · secrets · runs · wallet

No cross-tenant reads. No cross-tenant routing of sensitive runs.

tiers ▸ pick your isolation 05

You choose where sensitive runs execute

Local, managed cloud, or a hardened sandbox - sensitive material is never routed to another tenant's machine.

Local / BYO Runs on your own hardware with no compute charge. Reaches intranet-only systems; your AI keys stay on your machine.
Cloud Runs on the managed cloud fleet, metered by running time from your wallet beyond the included usage.
gVisor-isolated Sensitive runs execute in a gVisor-isolated cloud sandbox. Only non-sensitive runs can be served by foreign supply, and only with consent.

The rule. Sensitive material (credentials, secrets, persona logins) is never routed to another tenant's machine. Learn how venues are chosen on the agents page.

ownership ▸ your install, your data 06

Install a workflow - never someone else's credentials

Workflows installed from the marketplace are recipes only: steps and a manifest of the inputs they need. Every run uses the installer's own data.

Creator side

A creator's personas, credentials, secrets, and sessions are stripped at publish and never used on anyone else's run. A literal embedded secret blocks publish until it's parameterized.

Stripped at publish

Install side

Whoever installs attaches their own personas, secrets, and inputs. Runs resolve only the installer's tenant data - the cross-tenant path is install and run, never sharing credentials.

auth ▸ how you sign in 07

Authentication & MFA

Protect your account with multi-factor authentication, rotating sessions, and lockout on repeated failures.

TOTPmulti-factor authentication
One-timerecovery codes
Rotatingrefresh + logout revocation
Lockouton repeated failed logins

Connect or disconnect social sign-in from Settings. See the authentication docs.

rights ▸ export & delete 08

You own your data - export or delete it anytime

Export your data, or delete your account or organization, from Settings. Deletion cascades across every tenant-scoped resource, GDPR-aligned, with a DPA available.

Export Export your account data from Settings whenever you need it.
Delete account or org Deletion cascades across tenant-scoped resources - nothing lingers.
DPA available We offer a Data Processing Addendum and document our sub-processors.
use ▸ responsible use 09

Authorized automation, enforced

Writ is for your own accounts, your own data, and sites you have the right to access - and we build the guardrails to keep it that way.

We publish an Acceptable Use Policy, enforce a domain blocklist at every URL choke-point, and run live anomaly and abuse monitoring. Responsible use protects the whole platform - and it's a feature, not fine print.

Acceptable Use Policy Domain blocklist Abuse monitoring
report ▸ vulnerability disclosure 10

Found a vulnerability? Tell us - you have our safe harbor

We welcome good-faith security research and follow a coordinated-disclosure model. This is the policy referenced by our security.txt; report privately and give us reasonable time to fix before going public.

How to report

Email [email protected] - a PGP key is available on request; encrypt anything sensitive. Please do not open a public issue, post to social media, or disclose the finding to anyone else until we have coordinated a fix.

Email the security team

Please include

  • A clear description of the issue and its impact
  • Steps to reproduce, or a minimal proof-of-concept
  • Affected URL, endpoint, or component
  • Never real credentials, secrets, or another tenant's data - redact them

Safe harbor - no legal action We will not pursue or support legal action against good-faith research that follows this policy. Activity consistent with it is considered authorized; if you are unsure whether something is in scope, ask first at [email protected] before proceeding.

  • Respect the disclosure process and give us reasonable time to fix before going public
  • Only access your own account and data - never another tenant's
  • Do not exfiltrate data beyond the minimum needed to demonstrate the issue
  • Do not degrade service, run automated volumetric or DoS testing, or violate privacy or applicable law

In scope

  • The Writ Cloud web app, API, and marketplace
  • usewrit.app and its authenticated product surfaces
  • Authentication, session, MFA, and account-security flaws
  • Tenant-isolation, access-control, and secret-handling issues

Out of scope

  • Denial-of-service, volumetric, or automated load testing
  • Social engineering, phishing, or physical attacks on staff
  • Reports from automated scanners with no demonstrated impact
  • Third-party services and sub-processors - report those to their own programs

Response targets

Best-effort targets under coordinated disclosure - not a contractual SLA. If we cannot meet one, we will tell you and keep you updated.

Stage Target
Acknowledge receipt within 3 business days
Triage and severity assessment within 10 business days
Fix or mitigation plan for High / Critical within 30 days
Public disclosure coordinated - after a fix ships or 90 days, whichever comes first

We credit reporters in our advisories unless you ask to remain anonymous. There is no paid bug-bounty program at launch - intake is coordinated disclosure with safe harbor. A bounty may be introduced later; this section is authoritative until then.

compliance ▸ roadmap & sso 11

Compliance

We build to recognized security and privacy standards and align our controls with GDPR - with a signed DPA, data-erasure tooling, and documented sub-processors. We don't claim certifications we don't hold. For a current security review or DPA, contact us.

Single sign-on

SSO and audit features are available for larger teams. Talk to us about your requirements.

faq ▸ common questions 12

Security questions, answered

Where do my credentials and secrets live?
Persona passwords and 2FA seeds, vault secrets, mailbox tokens, network credentials, and saved auth sessions are Fernet-encrypted at rest with the platform encryption key. They are never returned through the API, shown to the AI navigation model, or written to logs.
Does my data ever leave my machine?
Not on local runs. Run Writ on your own hardware and pages, extracted data, credentials, and AI keys stay on your device with no compute charge. Data only reaches the managed cloud when you choose to run a workflow there.
Can one organization see another organization's data?
No. Every record - workflows, monitors, personas, secrets, agents, runs, and the wallet - is scoped to your organization's tenant ID and filtered at the data layer. Queries are tenant-filtered, so one organization can never read or act on another's data.
What is your compliance posture?
We build to recognized security and privacy standards and align our controls with GDPR, with a signed DPA, data-erasure tooling, and documented sub-processors. We don't claim certifications we don't hold. For a current security review or DPA, contact us.
Can I export or delete my data?
Yes. You can export your account data and delete your account or organization from Settings. Deletion cascades across tenant-scoped resources.
close ▸ verify it in the docs 13

See exactly how Writ protects your data.

Start on your own machine, on your own accounts, with your own data.

Writ runs on your own accounts, with your own credentials and data, on sites you are authorized to use.