Skip to content

Delega Labs

Security

Last updated September 11, 2026

How Delega protects workspaces, credentials and data.

Tenant isolation

Every record belongs to a workspace. The application authorises each request by role, and Postgres row-level security enforces isolation as a second layer.

Credential protection

Model and integration keys are encrypted with AES-256-GCM using a server-side key before storage, are never returned to the browser, and are only decrypted at the moment an agent calls a provider.

API keys are shown once at creation; only a SHA-256 hash is stored. Keys are scoped, environment-bound and revocable.

Access control

Owner, admin, editor and viewer roles are enforced on every API route. Privileged actions — credential changes, key creation, team changes, billing and data deletion — are written to an audit log.

Application safeguards

Input validation on every endpoint, rate limiting, request size limits, SSRF protection for agent web access, PII redaction in run logs, per-run and monthly spend caps, and human approval checkpoints.

Security headers include anti-framing, strict transport security and content-type protections.

Responsible disclosure

Please report vulnerabilities to hola@trydelega.ai. We aim to acknowledge reports within two business days.

Questions? Contact hola@trydelega.ai.