Security & data handling¶
A workflow only works if you can trust it with real business data. For more, see our Trust Center or contact our team.
Compliance and the Trust Center¶
Malleable is SOC 2 Type II certified. Our Trust Center is the source of truth for security questions: it holds the SOC 2 report, the list of sub-processors, and the details behind how we handle your data. If your security team needs the report or has a questionnaire, start there. Live uptime is on the status page.
Integration credentials¶
Workflows connect to outside tools with the tool's own sign-in (OAuth) or an API key you provide. That means:
- You grant access through the provider's own consent screen; Malleable stores the resulting token, not your password.
- An API key you enter never appears in chat history and is hidden from the AI. A key saved as a reusable connection is stored with your Malleable account and only sent to the tool it belongs to.
- For integrations built by Malleable, each workflow chooses whose account it uses: the workflow owner's or the person who started the run. Other tools use the connection the workflow's owner set up, for every run.
- You can revoke access at any time from the provider's security settings.
Questions¶
For anything deeper, see the Trust Center or contact support.