Overbuilt Book a walkthrough

Trust

Security & Data

Last updated: 2026-08-17

Buying agents means granting access to systems that run your business. These are the questions worth asking any vendor in that position, answered directly. Where we cannot yet answer something completely, this page says so rather than reaching for a comfortable phrase.

Access and control

Are high-risk actions approval-gated?

Yes, and this is the core design decision of the product rather than a setting. Every outbound action — an email that leaves your domain, a quote that reaches a customer, a payment-adjacent write — waits for a human to approve it. An agent prepares finished work; a person releases it.

Can access be revoked immediately?

Yes. Every integration is connected through your own system's permission model, so you can revoke it from there without asking us and without waiting for us. Revocation takes effect immediately and stops the agents that depend on that connection.

What permissions does each integration require?

Only what the agents you have bought need to do their jobs. An agent that reads your books to reconcile receipts is granted read access; it is not granted the ability to move money.

The exact scopes depend on which agents you buy and which systems they need to reach. We provide the full scope list for your configuration on request, before you connect anything.

Model providers

Which providers process our information, and is it used for training?

Two: OpenAI and Anthropic, both through their commercial APIs.

And yes — we learn from it. We use data processed through the service to improve the agents we build: their configuration, the prompt and evaluation libraries behind them, and the correction patterns that stop a mistake recurring.

We do not train foundation models. Neither provider trains on data submitted through their commercial APIs under their standard terms, and we do not operate training infrastructure of our own. What improves is the configuration layer we build and own.

We do not sell your data, we do not disclose your identity or confidential information, and we do not reproduce your data in work delivered to another client. We sign a non-disclosure agreement with every client, and the client agreement sets out the data licence and its limits in writing before anything is connected. Full detail on the Privacy Policy.

How are model changes tested before they reach production?

On your actual jobs, not on benchmarks. A model that scores better in public evaluations can still be worse at a specific real task, and we have seen exactly that: a newer, higher-benchmarking model failed eight out of eight times at a job its predecessor had completed twenty consecutive times. It did not ship. Nothing changes in your stack because a provider published a new version.

Storage and encryption

Where is data stored, and is it encrypted?

In three places, and we would rather name all three than leave you to discover the second one later:

Traffic to every public Overbuilt surface is encrypted in transit; the site enforces HTTPS with strict transport security, frame and content-type protections, a referrer policy and a permissions policy.

How are credentials and OAuth tokens stored?

Locally, on the single device housed with the client. Integration credentials are not held in a shared multi-tenant store, so there is no central pool of client credentials to breach.

If agents run locally, how do you monitor them around the clock?

Not by reaching into your device. There is no inbound connection into your hardware — no remote-access tunnel, no listening port, nothing on your network waiting for us to dial in. That is deliberate: a permanent way in would be the single largest risk in this architecture, so it does not exist.

We watch the two places the work is already visible:

Both signals are outbound by nature and read from infrastructure we already operate. The practical consequence for you: monitoring costs you no additional attack surface, and there is no credential of ours sitting on your network.

The honest limitation. If your device loses power or internet, agents stop running until it is back. We see the gap and will tell you — see the response commitment in the Terms — but we cannot run the work in the meantime, and a scheduled job missed during an outage is a job that did not happen.

People and retention

Can Overbuilt staff read our data?

Access is limited to the people who build and support your agents — in practice a very small team, not a support department. Access happens for configuration, support and troubleshooting, and for nothing else.

What happens to our data when we cancel?

You receive an export of your data. We retain what is necessary for legal, tax and accounting obligations, and otherwise hold data for up to one year after cancellation.

Logging and recovery

Are agent actions logged? Can we see an audit trail?

Yes. Every agent run is logged, and those logs are retained for the duration of your contract — agents build on their own history, so the record is part of how they work rather than an afterthought. Every tier also includes a monthly usage and cost report.

What backup and recovery exists?

Client data is backed up to external drives held with the client's device, and the hosted copy on our own infrastructure acts as a second location. Overbuilt's own internal systems write atomically and retain timestamped backups of every change, capped per file.

The honest limitation: the backup drive sits with the device it backs up, so a fire or theft at your premises takes both. The hosted copy is what survives that, and it is one of the reasons the online copy exists. Off-site backup of the local device is not included by default — ask if you want it.

Card payments

Overbuilt Technologies LLC is the merchant of record for Overbuilt's own fees and handles any dispute on them. Payments your customers make through a booking page we build are processed by Stripe into your merchant account — that money never passes through us, and chargebacks on it are between you and your processor.

Analytics

Do you track visitors on your own website?

We count page views on our own server and nothing more. No cookies, no identifiers, no per-visitor records, no third-party analytics vendor, and no cross-site tracking. The payload is the page path and the referring host name — that is all of it. Do Not Track is honored. Tallies are kept for up to 400 days.

We built it this way rather than installing a standard analytics product because we sell measurement, and pointing a third-party tracker at our own visitors while telling clients we take data seriously would be inconsistent. Full detail on the Privacy Policy.

What we do not have

We are not SOC 2 certified. For engagements at our size that certification is not usually asked for, and claiming a posture we have not been audited against would undermine everything else on this page. If your procurement process requires it, tell us before you buy rather than after.