01
Security is not a separate mode or an enterprise add-on. It shapes how access, environments, and secrets are handled from the start.
How Stashbase protects your secrets, and keeps coding agents inside the boundaries you set.
01
Security is not a separate mode or an enterprise add-on. It shapes how access, environments, and secrets are handled from the start.
02
Sensitive encryption and credential operations are limited to selected private services, with isolated responsibilities across internal systems.
03
Traffic between clients, APIs, integrations, and internal services is encrypted in transit to help protect against interception and unauthorized access.
The current product security baseline includes the same controls highlighted on the homepage.
Built-in key management system that ensures your data stays secure.
AES-256 encryption with multiple layers of protection ensures your data is protected.
Scoped encryption and isolated access boundaries help reduce exposure between workspaces and services.
How Stashbase keeps coding agents useful without handing them your credentials.
Agents receive placeholders. The proxy injects the real value only into requests that match your policy.
Each credential can be limited to specific hosts, methods, and paths. Anything that does not match is blocked.
Agents cannot read files you have denied or reach hosts you have not allowed. With the Docker backend, attempts to bypass the proxy are blocked too.
If the Docker sandbox cannot start, the run stops. It never falls back to running the agent unsandboxed.
Every proxy decision is logged with host, method, action, and status code. Secret values and request bodies are never logged.
Short answers to the most common security questions.