Skip to content

Security

A dedicated instance, confined agents and your own Anthropic account

Each business gets its own server, database and accounts. Agents work in a confined space, secrets stay encrypted, and actions that bind your business are set up to wait for your operator’s confirmation.

Ten safeguards

What protects your instance, from the server to the AI bill

These safeguards come from the server, the software and the way the Belowdecks team delivers each instance, so they hold even when an AI model gets something wrong.

  • An instance of your own

    Your server, database and accounts serve your business alone. No data passes from one client business to another.

  • Confined agents

    Each agent sees only its own working folder. The Belowdecks team switches confinement on when your instance is set up, then a test checks that it holds.

  • A vault for secrets

    Passwords and keys are encrypted at rest, redacted from logs and never exported. The API can store them but never read them back.

  • Access by group

    Members of your team are invited by email and get only their group’s permissions. A sign-in link issued from the server works once and expires after 15 minutes.

  • Confirmations configured at setup

    Actions that bind your business are set up to wait for your operator: a card in a conversation, a question during the run, or an approval before the agent starts.

  • Your Anthropic account, your limits

    Anthropic bills tokens to your own account, with the spending limit you set. Each agent also has a cost cap per run.

  • A record of every run

    Each run leaves a summary, its files, its cost and a verdict: Delivered, Partial or Blocked. You can stop a run in progress.

  • Your data belongs to you

    Export your projects at any time, with the contents of your collections if you want them. An export never contains secret values.

  • A backup every night

    The database, project memory and output files are archived every night, with rotation, on your instance’s server.

  • One switch to pause everything

    One button pauses the instance: no new run starts, whether it comes from a trigger, the API or a conversation.

Data flows

What leaves your instance, and where it goes

Your data is stored on your instance. Four flows leave it, and we name each one so you can record them in your own files.

  • Text an agent works on

    To do its work, an agent sends the text it handles to the provider of its AI engine, such as Anthropic for Claude Code, through your own account. That provider may process the text outside Quebec.

  • Email notices and reports

    Notices and confirmation requests sent to your operator go out through an email delivery service, and so does the monthly report.

  • Technical error reports

    When an error occurs on your instance, a technical report reaches the Belowdecks team through an error-tracking service, so it knows when something breaks.

  • Services you connect

    A webhook to one of your tools, an MCP server or the API of an application you open to an agent receives what you have chosen to send it.

Outside text is marked as data

An email, a web page or an end customer’s message can contain disguised instructions. Incoming text is therefore marked as data to handle, and the agent’s instructions tell it to flag any instruction it finds there instead of following it.

This marking lowers the risk without removing it, because an AI model can still be swayed. That is why actions that bind your business are set up to wait for your operator. In a conversation, your operator confirms a card that shows what will run. An autonomous agent, started by an email for example, is set up to prepare the work and put its question to your operator before any action that binds your business.

The security questions we hear most

Where does my data live?

On your dedicated instance: a server, a database and accounts that serve your business alone. We tell you at the diagnostic, before you sign, which region your server is hosted in, so you can record it in your own files.

Four flows leave the instance: the text an agent sends to the provider of its AI engine, through your own account; email notices and reports, sent through an email delivery service; technical error reports, which reach the Belowdecks team through an error-tracking service; and whatever you choose to send to the services you connect, such as a webhook to one of your tools.

Can an agent touch things it shouldn’t?

An agent sees only its own working folder. The confinement that keeps it there is switched on when your instance is set up, and a test confirms it works: a file outside the agent’s folder must stay invisible from inside, and each project’s settings must stay out of reach of the others. Credential files never leave with an agent’s results.

The same principle applies to people. A member of your team has only the permissions of their group. An end customer writing on your website sees only their own conversation, and their session expires after 12 hours.

What if an agent gets it wrong?

Actions that bind your business are configured during setup to wait for your operator’s approval: a confirmation card in a conversation, often a pre-filled form they can correct, or an approval before the agent starts. Before an agent is switched on, it goes through a rehearsal: real data, real tools, a throwaway workspace and an instruction to take no binding action. You then read its report on what it would have done.

Every run leaves a summary, its files, its cost and a verdict. You can stop a run in progress, or pause the whole instance in one move.

Does the Belowdecks team have access to my instance?

Yes. The Belowdecks team delivers and maintains your instance, and has access to it to keep it running, apply updates and answer your support requests. That access is governed by the agreement you sign with us. Answers to the agents and confirmations stay with your operator.

How does Belowdecks help with Law 25?

Quebec’s Law 25 asks you, among other things, to protect the personal information you collect and to be able to say where it is kept and who can access it. With Belowdecks, you can answer those questions precisely: your data sits on your dedicated instance; the text an agent handles goes through the provider of its AI engine; email notices go through a delivery service; technical error reports reach the Belowdecks team through an error-tracking service; secrets are encrypted; the Belowdecks team’s access is governed by your agreement.

The AI engine’s provider may process that text outside Quebec. If personal information is sent to it, your privacy impact assessment needs to cover that, and we raise it at the diagnostic.

The assistant on your website shows your customers, under the conversation, the privacy notice you write. Compliance with the law remains your business’s responsibility.

Where are backups kept?

Every night, one archive gathers the database, project memory and the files the instance keeps. Archives are stored on the same server as the instance, with rotation: the oldest is deleted when a new one is written. The instance’s health check flags a backup that is too old.

If you want a copy kept off that server, we discuss it at the diagnostic.

What does an export contain?

An export holds the definition of your projects: agents, skills, functions, triggers and collection schemas. The contents of your collections are added if you ask for them, up to a cap per collection, and the export always says when it was truncated. Run history and secret values are never part of it.

Your Anthropic account is opened in your name, and it stays yours if you stop.

Diagnostic

Bring your security questions to the diagnostic

Two hours on your processes, your data and what must stay under your control, then a written plan for a first cycle.