Delega Labs
Security
Last updated September 11, 2026
How Delega protects workspaces, credentials and data.
Tenant isolation
Every record belongs to a workspace. The application authorises each request by role, and Postgres row-level security enforces isolation as a second layer.
Credential protection
Model and integration keys are encrypted with AES-256-GCM using a server-side key before storage, are never returned to the browser, and are only decrypted at the moment an agent calls a provider.
API keys are shown once at creation; only a SHA-256 hash is stored. Keys are scoped, environment-bound and revocable.
Access control
Owner, admin, editor and viewer roles are enforced on every API route. Privileged actions — credential changes, key creation, team changes, billing and data deletion — are written to an audit log.
Application safeguards
Input validation on every endpoint, rate limiting, request size limits, SSRF protection for agent web access, PII redaction in run logs, per-run and monthly spend caps, and human approval checkpoints.
Security headers include anti-framing, strict transport security and content-type protections.
Responsible disclosure
Please report vulnerabilities to hola@trydelega.ai. We aim to acknowledge reports within two business days.
Questions? Contact hola@trydelega.ai.