roles · teams
Access you can explain
Vault and workspace roles show who can edit, run, and read without inventing a separate security product.
loading
Security
Each workflow step runs in its own container on a machine slot. Managed fleets supply short-lived compute; self-hosted fleets run on machines you enroll. Declared outputs and run records stay available after the containers are gone.
Each step runs in its own container, and that container runs on its own host machine from the fleet. Double isolation on a full host, not a micro-VM slice shared on a box. When the step ends, the container is gone and your record stays.
Each tile is one control your security team can point to, from how a run is isolated to the record it leaves behind.
scoped to your vault
Workflow definitions, run metadata, declared outputs, and structured Live Table data stay in your vault. Access follows vault and workspace roles.
Each run is sealed off. It can talk to the internet to do its job, but never to Trickest’s internal systems or another customer’s data.
isolated
Files and structured findings land in vault-scoped storage and transfer over HTTPS with time-limited signed URLs.
vault-scoped
Store secrets encrypted and reference them by name. A value is never shown back once you save it.
referenced by name
Managed fleets can pin static outbound addresses so the systems you scan allowlist the traffic.
opt-in
When a step finishes its container is gone. Declared outputs, logs, and run records stay under your retention settings.
per step
Search, filter, and export records of supported authenticated platform activity when the audit feature is enabled.
enterprise
People and automation authenticate under vault and workspace roles. Tokens act as the user. Enterprise audit logs cover supported platform activity.
Connect enterprise users through SAML 2.0. Individual users can add TOTP multi-factor authentication to password sign-in.
Assign vault and workspace roles to people or teams. Separate who administers, edits, runs, and only reads.
CLI, SDK, and API calls authenticate as the user. Regenerating a token invalidates the previous one.
Search, filter, and export records of supported authenticated platform activity when the audit feature is enabled.
Trickest holds ISO/IEC 27001. Use run history, roles, and audit exports in your own security reviews, and ask us for the certificate and current assurance documents.
roles · teams
Vault and workspace roles show who can edit, run, and read without inventing a separate security product.
run history
Execution records, outputs, and logs stay available so a review can follow what ran, when, and with which graph version.
reviews · export
Use platform records in customer security reviews. Ask us for current assurance documentation and scope.
Responsible disclosure
Found a security issue? Send the details and steps to reproduce. We confirm the report and work it with you.
security@trickest.com →Security documentation
Request our ISO/IEC 27001 certificate, sub-processor list, and current assurance documents for your review.
Request documentation →Execution is where steps run. Workflows and agents submit work into that model.
Get a personalized demo
A 30-minute walkthrough. We map the platform to your stack and answer pricing and deployment questions for your environment.