Security
Secure by default, from prototype to production
Every app on AppWeaver AI runs on isolated infrastructure with automated scanning, protected secrets, and round-the-clock monitoring — so security is built in, not bolted on.
Contact security teamPer-customer isolation
Each account runs in its own isolated cloud environment, so your data is separated at the infrastructure level, not just behind logical database rules.
Hardened project sandboxes
Every project runs in its own locked-down container with restricted system calls, keeping workloads separated from one another.
Secrets never touch your code
API keys and credentials are injected at runtime through a secure proxy. They never appear in your source, your editor, or the Agent’s context.
Automated pre-publish scanning
Before a project can be published, it is automatically scanned for common vulnerabilities, exposed secrets, and risky dependencies.
Continuous monitoring
Automated systems watch for anomalous activity around the clock and alert our security team the moment something looks wrong.
Enterprise access controls
Single sign-on, SCIM provisioning, and role-based access control let organizations manage who can view, edit, or publish projects.
Compliance program
We maintain a SOC 2 Type II report and align our practices with GDPR, with additional certifications on our roadmap.
Responsible disclosure
Security researchers can report findings through our Report Abuse page, and we work with outside partners to test our defenses continuously.