Security

Trust holds for the life of the machine.

Each workflow step runs in its own container on a machine slot. Managed fleets supply short-lived compute; self-hosted fleets run on machines you enroll. Declared outputs and run records stay available after the containers are gone.

Isolation follows how a step runs

Workflow jobs use containers on fleet machine slots. Managed agent sandboxes each get a separate cloud instance. These are distinct execution environments.

FLEETcloud instancecontainerMANAGED SANDBOX
Workflow step containers
Each workflow job gets its own container on a fleet machine slot. One slot runs one job at a time.
Managed sandbox instances
Each managed sandbox gets its own EC2 instance. Other Trickest sandboxes share neither its guest kernel nor container runtime.
Access follows your workspace
Vault and workspace roles control access to platform resources. Network controls restrict workload access to protected infrastructure.
Removed, record kept
Managed fleets spin machines up, or enroll your own. When the step ends the container is gone; your outputs and run records stay.

Separate cloud instances can share underlying AWS hardware. Access controls, patching, and network policy still matter. Read the sandbox guide

The controls behind a run

Each tile is one control your security team can point to, from how a run is isolated to the record it leaves behind.

scoped to your vault

What Trickest stores for a run

Workflow definitions, run metadata, declared outputs, and structured Live Table data stay in your vault. Access follows vault and workspace roles.

Scoped access

Workspace permissions govern access to run data. Separate managed sandbox instances keep unrelated sandboxes off the same guest OS.

isolated

Outputs over signed URLs

Files and structured findings land in vault-scoped storage and transfer over HTTPS with time-limited signed URLs.

vault-scoped

Secrets by name

Store secrets encrypted and reference them by name. A value is never shown back once you save it.

referenced by name

Static outbound IPs

Managed fleets can pin static outbound addresses so the systems you scan allowlist the traffic.

opt-in

Removed, record kept

When a step finishes its container is gone. Declared outputs, logs, and run records stay under your retention settings.

per step

Audit trail

Search, filter, and export records of supported authenticated platform activity when the audit feature is enabled.

enterprise

Access that matches how teams work

People and automation authenticate under vault and workspace roles. Tokens act as the user. Enterprise audit logs cover supported platform activity.

SAML single sign-on

Connect enterprise users through SAML 2.0. Individual users can add TOTP multi-factor authentication to password sign-in.

Roles that match how teams work

Assign vault and workspace roles to people or teams. Separate who administers, edits, runs, and only reads.

Personal API tokens

CLI, SDK, and API calls authenticate as the user. Regenerating a token invalidates the previous one.

Enterprise audit logs

Search, filter, and export records of supported authenticated platform activity when the audit feature is enabled.

Evidence for the reviews you already run

Trickest holds ISO/IEC 27001. Use run history, roles, and audit exports in your own security reviews, and ask us for the certificate and current assurance documents.

roles · teams

Access you can explain

Vault and workspace roles show who can edit, run, and read without inventing a separate security product.

run history

Runs you can reconstruct

Execution records, outputs, and logs stay available so a review can follow what ran, when, and with which graph version.

reviews · export

Evidence for your process

Use platform records in customer security reviews. Ask us for current assurance documentation and scope.

Responsible disclosure

Found a security issue? Send the details and steps to reproduce. We confirm the report and work it with you.

security@trickest.com →

Security documentation

Request our ISO/IEC 27001 certificate, sub-processor list, and current assurance documents for your review.

Request documentation →

questions

Frequently asked

Questions about the trust model? Get a demo.

Yes. What a run produces stays in your vault, scoped to your team and separated from other customers. Trickest runs your workflows and stores the results for you, nothing more.

Get a personalized demo

See Trickest in Action

A 30-minute walkthrough. We map the platform to your stack and answer pricing and deployment questions for your environment.