Security

Agents that can act, and can’t overstep.

Every action is checked against your rules before it happens. Keys stay out of the model. Everything is written down.

Agent access

Each job defines which systems and actions an agent can use, limited by account, action, recipient, amount, time or any condition you set.

Before an action runs, Shadway checks it against those rules. Allowed actions continue. Prohibited actions are blocked. Actions that need a decision pause for approval.

Credentials

API keys, passwords and connected accounts stay in Shadway’s vault, outside the model. The model can ask for an action; it never receives the credential used to carry it out.

You can revoke access to a connected service at any time.

Your data

Shadway processes the instructions, files and messages needed to do the work you set up. We don’t use your content to train a model.

When a job uses an email provider, website or API, Shadway sends that service only what the action needs.

Model providers

Shadway sends a model the job context it needs to decide what to do next. If you use your own provider account, that provider processes it under your agreement.

Records

Shadway keeps what it needs to run and recover long jobs: requested actions, permission checks, approvals, errors, responses and evidence of finished work. You can see what an agent asked to do, what Shadway allowed or blocked, and what happened next.

Retention

Retention depends on the kind of information, your plan, active jobs, security needs, billing records, backups and legal obligations. The Privacy Policy has the details.

More in the Privacy Policy and Terms. Questions or a questionnaire to fill in: yusuf@shadway.com.