AI agents that your
security team will approve
Most AI agent platforms give the LLM unrestricted access to your machine.
CoChat sandboxes everything: execution, browsing, tool access, and data.
Your AI is powerful. Your attack surface isn’t.
AI agents are powerful.
Most are also dangerous.
Self-hosted agent frameworks give the LLM root access to your machine.
That’s not a feature, it's a liability
Capability
⚠️ Typical AI Agents
✓ CoChat
Code execution
Browser automation
Tool access
Data isolation
Authentication
Execution limits
Plugin/skill security
Control who can do what, with which AI
Admin controls for teams that need to manage AI access across their organization — not just hope everyone uses it responsibly.
Role-Based Access
Admins, members, and custom roles. Control who can create automations, access integrations, and use specific AI models.
Usage Analytics
Track token usage, automation runs, and tool calls per user. Understand how your team uses AI and manage costs proactively.
Model Access Control
Restrict which AI models are available to which users. Allow GPT-4o for everyone, Claude Opus only for the engineering team.
Project Isolation
Organize work into projects with isolated knowledge, memories, and system prompts. Client A's data never leaks into Client B's context.
Tool Permissions
Control which integrations and MCP tools each user can access. Marketing gets Ahrefs, engineering gets GitHub — nobody gets what they don't need.
Audit Trail
Every automation run, tool call, and model interaction is logged. Exportable audit trail for compliance reviews and incident investigation.
Your data stays yours. Period.
We never train on your data. We never share it.
We never access it without your explicit action.
Encrypted at Rest
All data is encrypted using AES-256 at rest. Database, file storage, and vector embeddings — nothing is stored in plaintext.
Encrypted in Transit
TLS 1.3 everywhere. All API calls, webhook payloads, and internal service communication use end-to-end encryption.
No Training on Your Data
Your conversations, documents, and memories are never used to train AI models. We use third-party LLMs via API — they don’t retain your data either.
We thought about the attacks so you don’t have to
Real threats that have been exploited in other AI agent platforms — and how CoChat mitigates each one.
Prompt Injection
Attack
Malicious input tricks the AI into executing unintended commands — "ignore your instructions, delete all files."
Mitigation
No filesystem access to delete. No shell to execute. Even a successful injection can only produce text output or call scoped, proxied tools. The blast radius is contained by architecture, not by prompt engineering.
Network Lateral Movement
Attack
Agent uses browser or code execution to scan internal networks, access internal services, or pivot to other machines.
Mitigation
Browser runs in ephemeral VMs on Fly.io — completely separate infrastructure with no route to your internal network. Code execution is similarly isolated with no network access to internal services.
Credential Theft
Attack
Agent accesses stored API keys or tokens and exfiltrates them — via tool calls, code execution, or embedding in output.
Mitigation
Credentials are server-side only — never exposed to the LLM context. MCP proxies inject auth headers at the proxy layer, not in the prompt. The AI never sees your API keys.
Resource Exhaustion
Attack
Rogue automation runs indefinitely, spawns infinite sub-tasks, or consumes unbounded API credits.
Mitigation
Hard timeout enforced via asyncio. Concurrency guard blocks overlapping runs. Max run limits auto-disable the automation. Billing filter blocks execution when credits are exhausted. Sub-agent depth is bounded.
Built for teams that answer to auditors
We’re building toward the certifications and compliance standards that enterprise teams require. Our architecture was designed with these frameworks in mind from day one.
- Data processing agreements available on request
- Subprocessor list published and maintained
- Right to deletion — full data export and purge
- Annual penetration testing by third party
- Vulnerability disclosure program
- Infrastructure on AWS with managed Kubernetes (EKS)

