Security at Refline
Last updated October 1, 2026
Agents that touch revenue need to earn the same trust as people who do. Here's what we do about it, and what's still in flight.
Encryption everywhere
TLS 1.2+ in transit, AES-256 at rest. OAuth tokens and credentials are encrypted with per-workspace keys.
Scoped access, always
Agents act with the minimum permissions granted per tool, per room. Read-only stays read-only.
Human approval boundaries
External sends, record writes and spends pause for a named approver. Irreversible actions are never silent.
Immutable audit log
Every agent action carries actor, inputs, outputs, approver and timestamp. Exportable to your SIEM.
No shared-model training
Your workspace data never trains models used by other customers. Room memory is yours alone.
SOC 2 Type II, in progress
Our audit is underway. Controls are implemented today; the report follows the observation window.
Found something? Responsible disclosure: security@reflineai.com.