Security

Security at Malleable

Malleable is built from the ground up to safely handle your most sensitive information and integration connections.

SOC 2 Type II, tested and attested by Prescient Assurance

An independent auditor has reviewed our controls and attested that they meet SOC 2 Type II. That means the controls were tested in practice over a period of months, not checked once. The report and every control are in our Trust Center.

AI boundaries

Governance →

Malleable combines the best of agentic AI with the reliability of automation tools. That gives you several layers of control over what the AI can and can't do.

Tools
Each step of an operation can use only the tools it is given. Fixed steps and AI judgment →
Approvals
A step that needs a person waits for their decision before anything changes. Custom forms for handoffs →
Completion
A stage has to meet its completion criteria before the operation moves on.
Run history
Every run records what steps the AI took, and which actions were taken.
Changes
Every version of an operation is saved and can be restored. Changes Malleable suggests apply only after the owner approves them. Self-improving operations →
Slack and Teams
Malleable Bot asks before it uses anyone's access or changes anything. Malleable Bot →
Code sandbox
Code Malleable writes runs in an isolated sandbox for each run.

Your data

Encryption
TLS in transit. Datastores that hold customer data are encrypted at rest.
Model training
Your data is never used to train AI models.
Sub-processors
We have a rigorous process for choosing the providers that process your data, and every one is listed in our Trust Center. See the list →
Deletion
On request, all data related to your organization can be deleted. Enterprise customers can request custom retention windows for runs of their operations.

Sign-in and access

Secure login
People sign in with single sign-on, or a short-lived code sent by email.
Single sign-on (Enterprise)
Microsoft Entra, or any other SAML or OpenID Connect provider. Setup guide →
Enterprise
SCIM provisioning, custom roles, audit log export, and control over which integrations and models teams can use.

Connected apps and outside people

Security docs →
Connected apps
Connected through each app's own consent screen. We store a token, never your password, and you can revoke it from the app at any time.
Outbound requests
Go through a proxy that blocks private and internal addresses.
Outside people
Operations can have links that people without a Malleable account can open. Each link is a secure, unguessable URL unique to that interaction.

Our own security

Every control →
Production access
Only authorized staff with a business need, over encrypted connections with multi-factor authentication.
Vulnerabilities
External systems are continuously scanned, critical and high findings are fixed, and servers are patched routinely.