Security & trust

Your data. Your cloud. Your rules.

DEHA Lab is built around data sovereignty. The data side runs on your own infrastructure and we keep only the operational layer. The intelligence you build is a portable whole too, so nothing here locks you in.

Bring Your Own Cloud

Your data stays on your own infrastructure and never leaves it. We only run the operational layer on top.

Personal data protected

Sensitive details and personal data (PII) are detected and masked automatically, so they stay private.

Roles and access control

Fine-grained roles, single sign-on, and API keys put you in control of who can do what.

Isolation and audit

Every workspace is fully isolated, with usage limits and a complete, auditable activity trail.

How it is enforced

Eight controls, all on by default

Not a policy document. Each of these is a control the platform applies on every run.

Installed on your side

The platform runs on your own infrastructure. Your business data is read where it already lives and is never copied out to us.

Secrets stay encrypted

Connection details and keys are stored encrypted and decrypted only at the moment they are used. A resolved secret never reaches a log line.

Who can do what is explicit

Roles, single sign-on and API keys. Which agents, flows, screens and tables a person can reach are four separate limits, not one blanket permission.

Every workspace is separate

Workspaces are isolated from one another all the way down: data, configuration and usage counters never share a shelf.

A sensitive step asks first

Before an agent takes an action that matters, the flow stops and waits for your decision. Approve it and the run continues exactly where it paused.

Everything leaves a trail

Who changed what and when, and which run produced which result. All of it recorded, and all of it followable along a single thread.

Outbound calls are fenced

The platform only calls out to addresses you have allowed. Your internal network is off limits by default, and outgoing notifications are signed so the receiver can prove they came from you.

Limits are real limits

Usage caps per workspace and a ceiling on how much can run at once, so one heavy job cannot starve everything else on the system.

Agent safety

An agent runs inside your rules

An agent is the part of the platform that acts on its own, which makes it the part with the most limits drawn around it. These six apply to every run, and none of them is something the agent can turn off.

It only holds the tools you gave it

You pick which tools and which flows an agent may use. Everything outside that list is taken away before the model is even asked, so the agent never learns those tools exist.

It sees no more than you

An agent working on your behalf carries your access, and cannot widen it at any step. Which tables, which flows, which screens: your limit is its limit, and an agent it hands the work to stays inside the same one.

Only known addresses can trigger it

An endpoint that opens an agent to the outside world can be locked to the IP addresses and ranges you name. A call from anywhere else is refused, and an unsigned one is refused too.

Code runs in a sealed box

When an agent writes code to solve something, that code runs in a single-use container with no route to anything else. The container is destroyed when the job ends.

Personal data is masked on the way out

Whatever an agent sends out is checked for personal data and masked first. If that check cannot run, the answer does not leave. It is on by default and cannot be switched off.

Every run has a ceiling

How long it may run, how many times it may hand work on, how many jobs may run at once and how much it may spend. All four are capped, so an agent cannot loop forever or run up a bill on its own.

Ready when you are

Want to set it up? Come build with us.

We deploy DEHA Lab locally for you and walk you through the whole platform, end to end. Pick a time that works and we'll meet on Google Meet.

Deployed locally, for youThe full platform, end to endHands-on onboarding