Security
Last updated: July 17, 2026
OwlAgent acts on your email, calendar, files, and CRM — so protecting that access is the core of how we build. Here is, plainly, what we do.
Access to your accounts
- All third-party connections use OAuth 2.0. We never ask for, see, or store your passwords.
- Access tokens are stored encrypted, and the assistant uses them only to execute the requests you make.
- You can revoke OwlAgent's access at any time from each provider's security settings — revocation takes effect immediately.
Infrastructure
- The service is hosted on Hetzner, in European Union data centers.
- All traffic is encrypted in transit with TLS (HTTPS).
- Production access is limited to the founding team, on a least-privilege basis.
- Databases are backed up regularly.
Payments
All payments are processed by Stripe, a PCI-DSS Level 1 certified provider. Your card details are entered on Stripe's systems and never touch our servers.
Where we are honest about limits
We are a small team and do not yet hold formal certifications such as SOC 2 or ISO 27001. If you are evaluating OwlAgent for your business and have a security questionnaire, we will answer it directly and candidly — just email us.
Reporting a vulnerability
If you believe you have found a security issue, please email lorenzo.trichard@gmail.com with the details. We read every report and will respond quickly. Please give us reasonable time to fix an issue before disclosing it publicly.