Agents that can do things. On a leash.
Every Sprigr agent runs in an isolated environment with its own credentials, a named approval gate, and a complete audit trail. You see every action, and you can review any of them.
How we keep autonomous things trustworthy.
-
Isolation by default.
Every business gets its own database, its own storage, and its own execution environment. Data from one customer cannot reach another because nothing is shared to begin with.
- Dedicated per-tenant database and file storage, never pooled
- Integration credentials held in a vault and decrypted only at runtime
- Agent HTTP requests limited to approved domains, with an approval step for new ones
-
Approval gates with teeth.
Define exactly when an agent can act on its own, and when it must ask. Gates are policy, not prose. A gated step pauses the run and waits for a named approver.
- Review and approval gates on any workflow step
- Human sign-off required before destructive actions in marketplace apps, with undo on most
- Token budgets that warn at 80% and stop at 100%, plus a company-wide emergency stop
-
Full audit trail by construction.
Every action an agent takes is logged with its inputs, its outputs, and the approval decision that allowed it. You can review any decision after the fact.
- Every tool call, message, and approval logged with full context
- Message-level audits on every agent turn
- Retained under the terms in our privacy policy
-
Your data stays yours.
Sprigr never trains on your data. You choose which model each agent runs on, who can see what, and when it is deleted.
- Model choice per agent: Auto, Opus, Sonnet, or Haiku
- Per-user document access that respects your SSO groups
- Delete your account and your data is gone within 30 days
Your operations hub, but yours.
Most AI platforms run every customer on shared infrastructure. Sprigr does not. Every business gets its own isolated execution environment, credentials encrypted at rest, approval gates with teeth, and a full audit trail behind every action.
-
Isolated per tenant
Every customer gets its own database, file storage, and execution environment. No shared databases. No leaky neighbours.
-
Secrets encrypted at rest
API keys and credentials live encrypted in our vault, decrypted only inside your agent's sandbox at runtime.
-
Prompt-injection defences
System-prompt guardrails refuse credential extraction, a per-agent tool allowlist bounds what a compromised turn can call, and approval gates hold sensitive steps for a human.
-
Every action logged
Complete audit trail. You see exactly what ran, when, with what inputs, and who approved it.
- tenant
- your-org · isolated
- database
- one per tenant
- storage
- one bucket per tenant
- credentials
- vault · decrypted at runtime only
- http
- approved domains only
- tools
- per-agent allowlist
- sensitive steps
- approval gate · a person signs
- every action
- logged with inputs and approver
Questions about isolation, retention or a security review?
Founder-led. Chris answers security questions himself.