Security at Small

Agents can ship.
They do not get every key.

Small puts a narrow, auditable production boundary between a coding agent and your infrastructure. The controls below describe the implementation today—not a future certification claim.

14explicit launch gates
AES-256-GCMversioned secret encryption
Ed25519signed production releases

THE CONTROL BOUNDARY

Guardrails from prompt to production.

The platform assumes agents are powerful automation—not trusted infrastructure administrators. Every transition is authenticated, constrained, and attributable.

Identity and least privilege

Workspace roles, scoped service accounts, hashed API credentials, verified email, and optional company SSO keep human and agent access explicit.

Application secrets

Secrets are encrypted with a versioned AES-256-GCM keyring and released only to the exact authenticated runtime leasing a deployment.

Constrained workloads

Each application runs as a container with declared memory, CPU, process, capability, storage, and network boundaries.

Controlled ingress

Only verified application hostnames reach loopback or authorized relay targets. Private apps require short-lived, app-bound access sessions.

Auditable ownership and exit

Sensitive changes produce workspace-scoped audit records, and owners can export portable configuration and history without exporting reusable credentials.

Recovery by verification

Production backups are encrypted before upload and count as ready only after download, checksum verification, decryption, and a real restore drill.

REQUEST PATH

One narrow path. Five enforced boundaries.

01

Human or agent

Uses a session or least-privilege API token

02

Control plane

Authenticates, authorizes, schedules, and audits

03

Enrolled runtime

Leases only work assigned to its node identity

04

App container

Receives only its declared resources and secrets

05

Trusted gateway

Publishes only active, authorized hostnames

VULNERABILITY DISCLOSURE

Report security issues privately.

Use the contact published in our machine-readable security file. Include the affected component, likely impact, reproduction steps, and evidence with secrets and personal data removed.

Open security.txt

Use controlled data

Test only accounts, applications, and data you control. Stop and report immediately if you encounter another customer's information.

Avoid harmful testing

Do not exfiltrate data, disrupt availability, use social engineering, compromise third parties, create persistence, or run high-volume automated scans.

Coordinate disclosure

Give us a reasonable opportunity to investigate and remediate before publication. No bounty is currently promised, and the reporting channel does not authorize unlawful testing.

CURRENT ASSURANCE

Clear claims, including the limits.

Trust is easier when the line between implemented controls and future evidence is visible.

IMPLEMENTED

Software controls

Scoped identity, tenant-aware authorization, encrypted secrets, private access, audit records, credential-redacted customer exports, signed provider webhooks, bounded data retention, signed releases, backup verification, and aggregate monitoring are implemented and tested.

REQUIRED FOR LAUNCH

Provider evidence

Public DNS and TLS, signed transactional-email delivery, a real company SSO login, live billing, off-host recovery and alerts, and multi-host failover must pass the production readiness contract.

NOT CLAIMED

Certifications and SLA

Small does not currently claim SOC 2, ISO 27001, PCI certification, or a production availability SLA. Those claims will appear only after independent evidence supports them.

PRODUCTION WITHOUT THE MASTER KEY

Give your agent somewhere safe to ship.

Create your workspace