Security & control

Enterprise‑grade, by default

Agents act on your behalf, so the question is never just what they can do — it is who allowed it, what it cost, and where the record lives.

Controls

What an admin can set

SSO & SAML

SAML 2.0 · OIDC · enforced MFA

Role-based access

Per-department and per-member permissions

Audit logs

Every agent action · 180-day retention

Your cloud

Dedicated VPC or on-prem deployment

Data residency

Keep your data in-region

Cost controls

Budgets and caps: department → member

Deployment

Three places it can run

Our cloud

The managed default. Workspaces run isolated per user, with state that never crosses accounts.

Dedicated VPC

The same runtime inside your own cloud account, on infrastructure your team controls.

On-prem

For teams whose data cannot leave the building. holaOS is open source, so the runtime is auditable.

Data

What happens to what you put in

Your data is not training data

Files, memory and app data are never used to train models — ours or anyone else's.

Every action is attributable

Agent runs are logged with the workspace, the member and the tools they touched.

Credentials stay scoped

Connected accounts are granted per department, and can be revoked without touching the rest.

Security

Bring your security review

Send us your security questionnaire and we will work through it with your team.