Security and privacy

How Windlass isolates your workspace, handles your data, and what you can do to keep your work safe.

Windlass runs code on your behalf and handles files you care about. This page explains how your workspace is protected, what happens to your data and how to use the product safely.

Isolation

Each workspace runs in its own isolated container. The agent's shell commands, the code it runs, your project files and any connectors you configure all live inside that container, separate from every other account. Nothing another customer does can reach your environment, and nothing your agent does can reach theirs.

Encryption in transit

All traffic between your browser and Windlass, and between Windlass and the services it uses, is protected with TLS. This includes the Workspace, the Files page, uploads and downloads, and the requests made to the model.

How your data is processed

When you send a message, the relevant parts of the conversation, any attached files and the file contents the agent reads are sent to the model to generate a response. Windlass uses DeepSeek's models, so those prompts and attachments are processed by DeepSeek's API.

Windlass does not train models on your content. Your prompts, files, code and session history are used only to run your sessions.

Your data stays yours

Account security

Recommendations

The agent is capable and, depending on your permission preset, may act with some autonomy. A few habits keep that power safe:

Reporting a concern

If you believe you have found a security issue, or you have questions about how your data is handled, email [support email]. Include enough detail to reproduce the issue, and leave secrets and other people's personal data out of the report.