Backed bya16z SpeedrunFree

Security at Ambiguous.

How Ambiguous protects your workspace today, what we don't have yet, and how to report issues.

TLS 1.3 + AES-256
Workspace isolation
Encrypted at rest
Security architecture: three nested isolation boundaries protecting a central workspace node, with encryption, identity, and token expiration primitives

How we protect your data

Three architectural decisions that make data breaches structurally difficult, not just operationally unlikely.

Workspace A
Workspace B
ORM-LEVEL ISOLATION

Workspace isolation

Every workspace is scoped at the ORM level. Cross-tenant data access is structurally impossible. Not just policy-prohibited; architecturally prevented.

audit-log
14:32:01mail.sendAriaok
14:31:58docs.editMarcusok
14:31:45crm.updateAriaok
14:31:30auth.loginadmin@cook
14:31:12drive.uploadAriaok
Streaming. Every action logged.

Complete audit trail

Every action by every user and every AI coworker is logged with actor, timestamp, resource, and outcome. Immutable, queryable, exportable.

ENCRYPTION LAYERSActive
TLS 1.3 in transit
AES-256 at rest
Encrypted backups
Short-lived JWTs (15m)
Rotating refresh tokens

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest. JWTs expire in 15 minutes, refresh tokens rotate on every use. No plaintext secrets, no downgrades.

What we do today

Production security posture as of May 2026.

TLS 1.3 everywhere

All traffic encrypted in transit. No exceptions, no downgrades.

Encryption at rest

All data encrypted at rest using AES-256. Database, file storage, backups.

Workspace isolation

Every workspace is scoped at the ORM level. Cross-tenant data access is structurally impossible.

Password hashing

bcryptjs with cost factor 12. Passwords are never stored in plaintext.

Short-lived tokens

JWT access tokens expire in 15 minutes. Refresh tokens rotate on every use.

HTTPS-only

HSTS enforced. No HTTP fallback. Secure cookies with SameSite=Strict.

Rate limiting

Per-IP and per-account rate limiting on all API endpoints. Brute-force protection on auth.

Access reviews

Regular access reviews for all team members. Least-privilege by default. MFA required for all internal access.

Incident response

Documented incident response runbook. Notification within 72 hours of confirmed breach per GDPR.

What we don't have yet

Honest about our current scope. These are real gaps we intend to close.

SOC 2 Type II

Audit engagement started Q2 2026

In progress

ISO 27001

Planned after SOC 2 completion

HIPAA BAA

Not available today

FedRAMP

No current plans

Penetration testing report

Annual third-party pentest scheduled Q3 2026

In progress

Responsible disclosure

Found a vulnerability? We want to hear about it.

Email

security@ambiguous.ai

Direct email. No contact forms, no ticket queues. You reach the security team.

Encrypted communication

For sensitive disclosures, request our PGP public key via the email above. We will reply with the key and fingerprint for verification.

Disclosure window

90 days from report to public disclosure. We aim to acknowledge within 48 hours and provide a fix timeline within 7 days.

Trust artifacts

Real-time status and external references.

Frequently asked questions

All data is stored in US-based data centers with AES-256 encryption at rest. Backups are encrypted and retained for 30 days. See how Drive stores your files.
No. Every workspace is isolated at the ORM level. AI coworkers only access data within their assigned workspace. Cross-tenant access is structurally impossible.
No. Your data is yours. We do not sell, share, or use customer data for model training. AI coworkers run inference on your data only when you instruct them via the Developers API.

We follow a documented incident response runbook. Affected customers are notified within 72 hours per GDPR requirements. Fix timeline communicated within 7 days.

Contact the security team

Questions not answered here? Email us directly. We respond to every inquiry.

Start free. 17 apps included.

One workspace for your team and your agents. Sign up and every app is ready in seconds. No credit card, no setup, no per-seat charge.