Security & control
Enterprise‑grade, by default
Agents act on your behalf, so the question is never just what they can do — it is who allowed it, what it cost, and where the record lives.
Controls
What an admin can set
SSO & SAML
SAML 2.0 · OIDC · enforced MFA
Role-based access
Per-department and per-member permissions
Audit logs
Every agent action · 180-day retention
Your cloud
Dedicated VPC or on-prem deployment
Data residency
Keep your data in-region
Cost controls
Budgets and caps: department → member
Deployment
Three places it can run
Our cloud
The managed default. Workspaces run isolated per user, with state that never crosses accounts.
Dedicated VPC
The same runtime inside your own cloud account, on infrastructure your team controls.
On-prem
For teams whose data cannot leave the building. holaOS is open source, so the runtime is auditable.
Data
What happens to what you put in
Your data is not training data
Files, memory and app data are never used to train models — ours or anyone else's.
Every action is attributable
Agent runs are logged with the workspace, the member and the tools they touched.
Credentials stay scoped
Connected accounts are granted per department, and can be revoked without touching the rest.
Security
Bring your security review
Send us your security questionnaire and we will work through it with your team.