Agent security and data privacy

Updated: 2026-09-15Reading time: 5 min

Store secrets securely, apply role-based access controls, minimize PII exposure in prompts, and produce the audit-log evidence trail for SOC 2 and GDPR compliance.

Managing secrets securely

Never embed API keys, passwords, or tokens directly in node configurations or prompt text. Instead, store all credentials in Cotonity's Secret Manager (Settings > Secrets) and reference them with the `{{secrets.MY_SECRET_NAME}}` syntax. Secrets are encrypted at rest with AES-256 and in transit with TLS 1.3. They are never written to run logs, even when the node that uses them fails. Rotate secrets regularly and give each integration its own dedicated secret rather than sharing one key across multiple agents — this way, rotating or revoking one integration's key does not affect others.

Access controls and permissions

Cotonity's role-based access control (RBAC) system lets you assign workspace members one of four roles: Viewer (read-only access to run history and metrics), Editor (can build and test agents but cannot deploy to production), Publisher (can deploy agents), and Admin (full control including billing, member management, and audit log access). For sensitive agents that handle PII or financial data, restrict the Editor role to only the team members who genuinely need to modify that agent. Use workspace-level agent folders and set folder-level permissions to segment access by team or function.

Minimizing data exposure in prompts

When passing customer or user data into an LLM prompt, send only the fields the agent actually needs — not entire database records. For example, if the agent only needs a customer's account tier to personalize a response, pass `{{steps.crm.output.tier}}` rather than the full CRM object. Be especially careful with fields that constitute PII under GDPR, CCPA, or other regulations: names, email addresses, phone numbers, and financial identifiers. Review your prompt templates regularly and remove any fields that crept in during development but are not necessary for the agent's function. Consider using data-masking transformations for fields like card numbers or SSNs.

Audit logs and compliance

Every action taken in your Cotonity workspace — publishing an agent, modifying a secret, changing permissions, initiating a manual run — is recorded in the Audit Log (Settings > Audit Log). Audit log entries include the actor's identity, the action performed, the resource affected, a timestamp, and the source IP address. Logs are retained for 90 days on Business plans and 365 days on Enterprise plans. You can export logs to your SIEM or compliance storage by configuring a log-streaming destination (Settings > Log Streaming). For SOC 2 or ISO 27001 compliance reviews, the audit log combined with run history provides a complete evidence trail for your agent automation activities.