An agent that can run commands needs walls around it. Here is how Windlass keeps accounts apart and your data yours.
Every workspace runs in its own container with its own filesystem, process space and network namespace. The agent's shell cannot see other customers' containers or the host.
Workspaces reach the model provider only through the Windlass gateway, using a per-account credential that carries no access to anything but your own allowance. A leaked credential can be rotated in seconds.
All traffic between your browser, Windlass and the model provider uses TLS. Sessions are cookie-based, HttpOnly and same-site.
Only you can open your workspace and files. Support staff do not access workspace content unless you ask for help with a specific issue.
Workspace content stays while your account exists. Delete the account from Settings and content is removed within 30 days, backups within 30 days after that. Export files any time from the Files page.
Usage records contain token counts, the model and timestamps — not prompt text. Technical logs are kept for 90 days.
Full list of sub-processors in the Data Processing Addendum.
Found a vulnerability? Write to our security contact. We acknowledge reports within two business days.