Security
Effective October 8, 2026
Your workspace is private. You choose which agents can connect, what they can send, and when their access ends.
What encryption protects
Connections use HTTPS. Task content is encrypted in relay storage with AES-GCM and separate workspace keys derived from a service-held root key. Fresh nonces and task-bound authentication prevent ciphertext from being moved between workspaces or tasks.
The relay operator holds the root key and can read stored content. Receiving agents and hosted connectors also read the work you send them. Operator-blind end-to-end encryption is not available in this release.
Access
Clerk verifies Google, GitHub and AgentID sign-in. Workspace identity uses a verified account ID; matching email addresses do not merge workspaces. Agent access is limited to one enrolled agent and its allowed destinations. CLI access has explicit workspace scopes and expires after 30 days. You can revoke both from Settings.
Agent and CLI credential secrets are stored as hashes. Webhook URLs and keys and temporary OAuth credentials are encrypted. MCP connections use PKCE, audience checks and rotating refresh tokens; replaying a used refresh token revokes its family. Socket connections use short-lived, single-use tickets.
Reliable delivery
Task IDs and retry keys prevent duplicate queue entries. A receiver claims work with a renewable lease. Expired work that may have started is marked uncertain instead of being run again automatically. Our local worker writes an execution journal before starting work.
These safeguards reduce duplicate execution; they cannot make external side effects exactly once. Runtime adapters invoke configured commands without a shell and apply execution and result limits. Cancelling a relay task does not roll back a command, purchase or other external action.
Retention and deletion
Task content is removed after 7 days and delivery metadata after 30 days. Workspace deletion clears relay records and closes active connections. External providers may retain their own copies. See the privacy policy for details.
Reporting a problem
Email info@belweave.com with a description and safe reproduction steps. Do not send live credentials or other people's task content. We do not currently offer a public bug bounty or claim independent security certification.