Security
Last updated: July 17, 2026
OwlAgent acts on your email, calendar, files, and CRM — so protecting that access is the core of how we build. Here is, plainly, what we do.
Access to your accounts
- Third-party connections use OAuth 2.0 wherever the provider supports it (Google, Microsoft, Notion, HubSpot and most others): you grant access on the provider's own consent screen and we never see your password. Where a provider only offers a password or an API key (IMAP mailboxes, a few API-key integrations), the credential is encrypted at rest with a key held outside the database, or passed straight to our integration vault and never stored on our servers. You can remove any connection at any time.
- Access tokens are stored encrypted, and the assistant uses them only to execute the requests you make.
- You can revoke OwlAgent's access at any time from each provider's security settings — revocation takes effect immediately.
Infrastructure
- The service is hosted on Hetzner, in European Union data centers.
- All traffic is encrypted in transit with TLS (HTTPS).
- Production access is limited to the founding team, on a least-privilege basis.
- Databases are backed up regularly.
Payments
All payments are processed by Stripe, a PCI-DSS Level 1 certified provider. Your card details are entered on Stripe's systems and never touch our servers.
Where we are honest about limits
We are a small team and do not yet hold formal certifications such as SOC 2 or ISO 27001. If you are evaluating OwlAgent for your business and have a security questionnaire, we will answer it directly and candidly — just email us.
Reporting a vulnerability
If you believe you have found a security issue, please email team@kendle.xyz with the details. We read every report and will respond quickly. Please give us reasonable time to fix an issue before disclosing it publicly.