Security & data handling

A workflow only works if you can trust it with real business data. For more, see our Trust Center or contact our team.

Compliance and the Trust Center

Malleable is SOC 2 Type II certified. Our Trust Center is the source of truth for security questions: it holds the SOC 2 report, the list of sub-processors, and the details behind how we handle your data. If your security team needs the report or has a questionnaire, start there. Live uptime is on the status page.

Integration credentials

Workflows connect to outside tools with the tool's own sign-in (OAuth) or an API key you provide. That means:

  • You grant access through the provider's own consent screen; Malleable stores the resulting token, not your password.
  • An API key you enter never appears in chat history and is hidden from the AI. A key saved as a reusable connection is stored with your Malleable account and only sent to the tool it belongs to.
  • For integrations built by Malleable, each workflow chooses whose account it uses: the workflow owner's or the person who started the run. Other tools use the connection the workflow's owner set up, for every run.
  • You can revoke access at any time from the provider's security settings.

Questions

For anything deeper, see the Trust Center or contact support.