ENDS AUGUST 30

11 / 2,489

Back the launch · $891

SECURITY

The security behind your AI worker.

Built so a worker can join your meetings, read your systems, and speak for your business without ever holding more access, authority, or data than you gave it.

Reviewed before we could ship.

DelegateWorker is approved on the Zoom App Marketplace: our OAuth scopes, data handling, and real-time media access passed Zoom's security review before the listing went live.

Zoom integration

Your cloud, your rules.

For Microsoft Teams, the worker deploys inside your own tenant: behind your firewall, your security policies, and your data boundary. Nothing leaves your cloud.

Enterprise deployment

Always disclosed.

The worker introduces itself as an AI in every conversation: meetings, calls, and messages. Trust with the people it talks to is the product, not a casualty of it.

Compliance

We publish where we actually are. Statuses on this page update as audits complete, not before.

StandardStatusCoverageDocumentation
Zoom App MarketplaceApprovedFull marketplace security review of OAuth scopes, data handling, and RTMS real-time media access, completed before public listing.Public marketplace listing.
GDPRAlignedEU data protection principles applied across collection, storage, and deletion.DPA available on request.
CCPAAlignedCalifornia consumer privacy requirements reflected in our privacy practices.See privacy policy.
SOC 2On our roadmapControls implementation planned; timeline shared with enterprise customers under evaluation.Ask us where we are.
ISO 27001On our roadmapISMS scoping planned alongside SOC 2.Ask us where we are.

What the worker does. What it does not.

Does

  • Encrypts in transit and at rest

    TLS in transit, encrypted storage at rest, secrets in environment vaults.

  • Scopes access per organization

    Workers, knowledge bases, memos, and integrations are isolated per customer organization.

  • Lets you bring your own model keys

    Run inference on your own OpenAI or Anthropic API keys under your agreements.

  • Revokes instantly

    Disconnect an integration, pause a worker, or end a session from the dashboard at any time.

Does not

  • Train on your data

    Your conversations, documents, and memos are not used to train models: not ours, and not our inference providers' under their API terms.

  • Hide what it is

    No human impersonation, ever. Disclosure is not configurable off.

  • Exceed its authority

    Observer, Voice, or Proxy: the worker acts at the level you set and escalates anything outside its brief.

  • Share across customers

    No cross-organization access to knowledge, memory, or integrations.

AI workers introduce new risks. We designed for them.

Prompt injection

Content the worker encounters in meetings and documents is treated as information to reason about, not instructions to follow. High-consequence actions sit behind the authority levels you set.

Authority creep

The Observer / Voice / Proxy dial is a hard product boundary, not a prompt. A worker set to Observer cannot commit your business to anything.

Data boundaries

Each organization's knowledge base is the only memory the worker brings to your conversations. Export or delete it on request.

Credentials

  1. 1

    OAuth-first integrations with minimal scopes.

  2. 2

    API keys stored server-side and never exposed in conversation context.

  3. 3

    Admin-controlled connect and one-click revoke.

Sub-processors

Inference and infrastructure run on named providers. No surprise vendors.

ProviderRoleNote
AnthropicLanguage model inferenceAPI traffic is not used to train models.
OpenAILanguage model inferenceAPI traffic is not used to train models.
ElevenLabsVoice synthesis and conversation runtimeVoice and conversation processing.
ZoomMeeting media via RTMSReal-time meeting audio under marketplace-approved scopes.
TwilioTelephony, SMS, WhatsApp carriage
StripePaymentsCard data never touches our servers.
SupabaseDatabase and storageEncrypted at rest.
VercelWeb hosting
Fly.ioWorker runtime hosting
ResendTransactional email (memos)

Responsible disclosure

Found something? Tell us at security@delegateworker.com. We would rather hear it from a researcher than read about it later. Meaningful findings get our thanks and public credit if you want it.

FAQ

Does the worker's AI model see our API keys?

No. API keys are stored server-side and never exposed in conversation context. You can also bring your own OpenAI or Anthropic keys under your agreements.

Is our data used to train AI models?

Your conversations, documents, and memos are not used to train models: not ours, and not our inference providers' under their API terms.

Can the worker act without our approval?

Only within the authority level you set: Observer, Voice, or Proxy. The dial is a hard product boundary. Anything outside the brief escalates to a human.

How is our organization isolated from others?

Workers, knowledge bases, memos, and integrations are isolated per customer organization. There is no cross-organization access to knowledge, memory, or integrations.

Deploying across a department? Bring your security team.

Talk to us