Security at Capy
SOC 2 Type II, isolated agent environments, scoped access.
The Basics
SOC 2 Type II
Independently audited controls for security, availability, and confidentiality.
Isolated by Design
Agent work runs in isolated cloud execution environments scoped to the repositories, integrations, and configuration you authorize.
You Stay in Control
Repository permissions, environment variables, model choices, and enterprise SSO options are configurable by your team.
How We Protect Your Code
Security controls span infrastructure, product workflows, and AI-provider data handling.
Production systems use encryption in transit, encryption at rest where supported, access controls, monitoring, and change-management processes.
Enterprise Security
For organizations with additional security requirements.
Customer-specific environment or infrastructure arrangements by agreement
Custom data-processing terms
Audit logging and export options by agreement
Enterprise SSO options
Security review, dedicated support, and custom contract terms
FAQ
Common questions about security at Capy.
Is Capy SOC 2 compliant?+
How does Capy handle AI provider data?+
Where is my data processed?+
How do I report a security vulnerability?+
Ship with confidence
Security-conscious controls from day one. Start building with Capy today.




