Security

How Stashbase protects your secrets, and keeps coding agents inside the boundaries you set.

01

Built into the product

Security is not a separate mode or an enterprise add-on. It shapes how access, environments, and secrets are handled from the start.

02

Service isolation

Sensitive encryption and credential operations are limited to selected private services, with isolated responsibilities across internal systems.

03

Secure transmission

Traffic between clients, APIs, integrations, and internal services is encrypted in transit to help protect against interception and unauthorized access.

Core controls

The current product security baseline includes the same controls highlighted on the homepage.

Key management system

Built-in key management system that ensures your data stays secure.

Multi-layer encryption

AES-256 encryption with multiple layers of protection ensures your data is protected.

Workspace isolation

Scoped encryption and isolated access boundaries help reduce exposure between workspaces and services.

Agent access

How Stashbase keeps coding agents useful without handing them your credentials.

Placeholders, not secrets

Agents receive placeholders. The proxy injects the real value only into requests that match your policy.

Per-secret rules

Each credential can be limited to specific hosts, methods, and paths. Anything that does not match is blocked.

Enforced by a sandbox

Agents cannot read files you have denied or reach hosts you have not allowed. With the Docker backend, attempts to bypass the proxy are blocked too.

Fails closed

If the Docker sandbox cannot start, the run stops. It never falls back to running the agent unsandboxed.

Metadata-only audit logs

Every proxy decision is logged with host, method, action, and status code. Secret values and request bodies are never logged.

Docs

Read the full security documentation for architecture details, encryption flows, platform boundaries, and how agent access is enforced.

FAQs

Short answers to the most common security questions.