afka runs agents that connect to your tools and act on your behalf, so security and control are built into the product. This page summarizes how we protect your data and how you stay in control of what your agents can do.
We design afka so that powerful automation stays under your control. Sensitive actions can be held for approval, every action is logged, spending is capped, and your data is isolated and encrypted. Security is not a single feature — it runs through our infrastructure, our application, and the controls we put in your hands.
afka runs on reputable cloud infrastructure providers that maintain strong physical and network security and their own industry certifications. Our production environment is logically separated from development and testing, and access to it is restricted and monitored.
Data is encrypted in transit using TLS and encrypted at rest. Connection tokens and other secrets are held in an encrypted secrets vault rather than in plain configuration, and are decrypted only when needed to perform your tasks.
Each customer Workspace is logically isolated, with separation enforced at the database layer so that one customer cannot access another's data. Tasks run scoped to the Workspace that initiated them.
When you connect a third-party app, authorization is handled by a managed integration layer — afka never receives your third-party passwords. The resulting access tokens are stored in the encrypted vault and used only to carry out the work you request. You can review and disconnect any connected account at any time, which revokes afka's access.
Tasks and any generated code run inside an isolated, secure sandbox, separated from other workloads. You choose how much autonomy each agent has, and sensitive or irreversible actions can be gated so they wait for your explicit approval before they run. Spending caps and allow-lists keep automated activity within limits you set.
Every action an agent takes — along with approvals, rejections, and the credits each action used — is written to an append-only audit log scoped to your Workspace. The log is designed so entries cannot be silently altered, giving you a reliable record of what happened, when, and why.
We apply least-privilege, role-based access controls across our systems. Staff access to production is limited to those who need it, granted for specific purposes, and logged. Customer accounts support email and single sign-on with Google or Microsoft, and roles let you control what members of your Workspace can do.
We follow secure software-development practices, including code review, dependency and vulnerability scanning, and separation of secrets from source code. Changes are tested before release, and we keep our dependencies up to date to reduce exposure to known vulnerabilities.
We monitor the Service for reliability and security events using logging, error monitoring, and alerting. We maintain backup and recovery processes appropriate to the Service so that data can be restored in the event of a failure.
Because afka acts on your behalf, we give you controls to keep it safe: autonomy levels (from draft-only to approval-gated to automatic within limits), approval gates for sensitive steps, allow-lists, and spending caps. We do not sell your data, and we do not use your workspace content to train third-party foundation models — see our Privacy Policy for details.
We align our practices with recognized security and privacy standards and support customer compliance through our Privacy Policy and DPA, including GDPR-aligned data handling. As we grow, we are pursuing formal certifications and independent assessments; we will publish them here once obtained rather than claim them before they are earned.
We welcome reports from security researchers. If you believe you have found a vulnerability, please email support@afka.ai with details and steps to reproduce, and give us a reasonable opportunity to investigate and remediate before any public disclosure. Please do not access or modify data that is not yours, degrade the Service, or run intrusive automated scans. We appreciate good-faith research and will not pursue action against researchers who follow this guideline.
Security is a shared responsibility. You help keep your Workspace safe by using strong, unique credentials and enabling single sign-on where possible, managing who has access, connecting only the accounts you need, and setting autonomy levels, approval gates, and spending caps that match your risk tolerance. Review your audit log regularly and disconnect accounts you no longer use.
Questions about security, or need documentation for a vendor review? Email support@afka.ai and we will be glad to help.
Afka, Inc.
2810 N Church St STE 89857
Wilmington, DE 19802
United States