Security
Last updated 9 October 2026
AgentDoorman sits between your AI agent and your apps. This page says, in plain words, how we keep that safe — and what we deliberately never hold.
We never hold your app logins
- You connect each app by signing in on that app's own page. The access it grants is held by Composio, our connections partner. We keep only an id for each connection — no passwords, no OAuth tokens, no API keys.
- Your agent never sees that access either. It asks us; we check your rules; Composio runs the action.
Your rules are enforced on our server, outside the agent
- Every single call your agent makes is checked on our server against your House Rules, Lock the Doors and Look, don't touch — before anything reaches your app.
- Because the rules don't live in your agent, a long chat, a compacted memory or a cleverly worded email can't talk them away. Nothing your agent can call reads or changes your rules, the lock, your Telegram link or your billing; only you can, signed in.
- Anything we can't classify is treated as a change, so it asks you first. Our own internal tools that could run other actions in one go are refused outright.
- Approvals come only from the Telegram chat you linked, and each is carried out at most once. If you lock the doors, make an app read-only or check an agent out while a request waits, it's turned away.
Agents and their keys
- Each agent you check in gets its own random key, shown to it once. We store only a one-way hash of it.
- Check an agent out on the Front Desk and its key stops working at once.
- An agent making far too many calls in a minute is paused automatically, and you're told — so a loop can't run up your apps or your bill.
What we log, and what we never log
- We log which action ran, in which app, what your rules decided, whether it worked and how long it took — that's your Guest Book.
- We never log what was sent or read: not the contents of your emails, messages or files, and not the details your agent passed in.
- Our error logs strip out secrets and query values before anything is written.
Requests waiting for your OK
- While a send waits for your tap, its details are stored encrypted (AES-256-GCM) and deleted the moment you decide — or after 30 minutes if you don't, when it expires unsent.
- If your agent picks up a result a little later, that result is kept encrypted for 15 minutes and then deleted.
In transit and at the edges
- Everything is served over HTTPS only, with strict browser security headers.
- Messages from Telegram, Dodo Payments and Composio are checked for their signature or secret before we act on them, and each is acted on once.
- Payments are handled by Dodo Payments, our merchant of record. We never see your card.
Deleting your account
Delete your account from the Front Desk at any time. In this order: any subscription is stopped, every app connection is removed at Composio, and then everything we keep about you is deleted. The one thing we keep is a one-way hash of your email address, so the free trial can't be taken twice — it can't be turned back into your address. Dodo Payments keeps the payment records the law requires. See the privacy policy.
Reporting a security issue
If you think you've found a vulnerability, email hello@agentdoorman.com with "Security" in the subject and enough detail for us to reproduce it. Please give us a reasonable chance to fix it before telling anyone else, and don't access other people's data or disrupt the service while testing. We'll reply, keep you posted and thank you once it's fixed.