Security

Built to be trusted with real access

Handing an agent write access to your systems only works if the platform underneath it is airtight. Here's how NeoSpec keeps it that way.

Your data, your infrastructure

When self-hosted, NeoSpec runs entirely inside your own network. Your code, secrets, and agent run history never leave your infrastructure unless you choose NeoSpec Cloud.

Isolated runtime sandboxing

Every agent executes inside its own Docker runtime. Agents can't see each other's filesystem, environment, or in-flight state — a compromised or misbehaving agent stays contained.

Encrypted key custody

BYOK provider credentials are encrypted at rest and only decrypted inside the runtime of an agent explicitly granted access to them.

Full audit trail

Every tool call, integration access, and dollar spent is logged with the run it belongs to, so you can reconstruct exactly what an agent did and why.

Deployment control

Self-host on infrastructure you already run, or use NeoSpec Cloud's managed deployment — both run the identical, open-source runtime.

Compliance roadmap

SOC 2 Type II and configurable data-residency regions are on the roadmap for NeoSpec Cloud. Get in touch if these are a requirement for your rollout.