Skip to main content

Security Overview

Deeployd is built with enterprise security in mind. From authentication to audit logs, every layer is designed for compliance and control.

Security Center

Business and Enterprise users can access all security features from the Security Center hub in the top navigation bar. The Security Center provides a unified interface for managing approvals, audit logs, SSO, SCIM, incidents, and more. Learn more about Security Center.

Security Architecture

┌─────────────────────────────────────────────────┐
│ Users │
└──────────────────────┬──────────────────────────┘


┌─────────────────────────────────────────────────┐
│ Authentication Layer │
│ • JWT tokens • API keys • SSO/SAML • MFA │
└──────────────────────┬──────────────────────────┘


┌─────────────────────────────────────────────────┐
│ Authorization Layer │
│ • RBAC • Permissions • Tenant isolation │
└──────────────────────┬──────────────────────────┘


┌─────────────────────────────────────────────────┐
│ Audit Layer │
│ • Action logging • SIEM export • Alerts │
└─────────────────────────────────────────────────┘

Key Security Features

Authentication

FeatureDescription
JWT TokensSecure session management
API KeysProgrammatic access
SSO/SAMLEnterprise identity providers
MFA/2FAMulti-factor authentication

Authorization

FeatureDescription
RBACRole-based access control
PermissionsGranular permission model
Tenant IsolationData separation
ApprovalsHuman oversight for sensitive ops

Compliance

FeatureDescription
Audit LogsComplete activity history
SIEM IntegrationExport to security tools
Data RetentionConfigurable policies
SCIMAutomated user provisioning

Security by Plan

FeatureStarterProBusinessEnterprise
JWT AuthYesYesYesYes
API Keys525100Unlimited
MFA/2FA-YesYesYes
SSO/SAML--YesYes
SCIM--YesYes
Audit Logs7 days30 days90 daysCustom
SIEM Export---Yes
Custom Retention---Yes
IP Allowlisting---Yes
Custom SLAs---Yes

Data Protection

Encryption

StateMethod
In TransitTLS 1.3
At RestAES-256
SecretsAES-256 with key rotation
BackupsEncrypted with separate keys

Data Residency

Enterprise customers can choose data location:

  • US: Virginia, Oregon
  • EU: Frankfurt, Ireland
  • APAC: Singapore, Sydney

Data Retention

Default retention periods:

Data TypeDefaultConfigurable
Conversations90 daysYes
Audit Logs30 daysYes
Agent Memory90 daysYes
Task History30 daysYes

Compliance Standards

Deeployd maintains compliance with:

  • SOC 2 Type II - Security, availability, confidentiality
  • GDPR - EU data protection
  • CCPA - California privacy
  • HIPAA - Healthcare (Enterprise)
  • ISO 27001 - Information security (in progress)

Security Best Practices

1. Use SSO When Possible

// Enterprise: Enforce SSO for all users
await client.settings.update({
authentication: {
requireSso: true,
allowedDomains: ['company.com']
}
});

2. Enable MFA

// Require MFA for admin users
await client.settings.update({
authentication: {
mfaRequiredRoles: ['owner', 'admin']
}
});

3. Rotate API Keys

// Rotate keys regularly
await client.apiKeys.rotate('key-123');

4. Review Audit Logs

// Regular security reviews
const logs = await client.audit.list({
severity: 'critical',
startDate: '2024-01-01'
});

5. Use Least Privilege

// Assign minimal permissions
await client.users.updateRole('user-123', {
role: 'member', // Not admin
permissions: ['agent.read', 'agent.chat']
});

Security Contact

For security issues or vulnerability reports, please email security@deeployd.com.


Next: Learn about Authentication in detail.