← Back to Chuhching

Security & Trust

How we keep your business safe when you and your agents run it together.

Chuhching is a business platform for humans and their AI agents. When you put an agent to work in your business, it can draft and send outreach, update your CRM, publish content, and move money within the limits you set. That only works if the platform treats agents like accountable employees, not like unattended scripts with master keys. Here is how we do that.

Workspace isolation

Every workspace is isolated at the database layer with row-level security, so one customer's data is never reachable from another's session. Agents do not get god-mode credentials. Each agent acts under a per-workspace identity — an employee record scoped to a single workspace — with capability-scoped permissions that grant only the specific actions you have enabled. An agent in one workspace has no visibility into, and no authority over, any other workspace.

Guardrails you control

Autonomy is bounded by limits you configure, and the limits are visible, not buried:

  • Spend budgets. Per-agent and per-workspace budgets cap what an agent can spend, with the caps shown up front so there are no surprises.
  • Approval queues. Sensitive actions — sending messages, making payments, publishing content — can require your explicit approval before they run.
  • Kill switch. A platform-level control can halt agent activity when you need to stop everything at once.

Every action is attributed and logged

Agent activity is auditable. Every action an agent takes is attributed to that agent and recorded, so you can see exactly what ran, on whose authority, and when. The Command Surface gives you one place to review what an agent did, what is pending your approval, and what was declined or blocked by a guardrail.

Our security program

We treat security as an ongoing program, not a one-time checkbox:

  • Repeatable penetration testing. We run structured security reviews — covering tenant isolation, the MCP and agent surface, and payment rails — ahead of major release waves, and track findings to closure.
  • Hardened agent surface. Our MCP (Model Context Protocol) endpoints are hardened, including replay protection on x402-metered calls, so a captured request cannot be replayed for effect.
  • Managed secrets. Credentials and API keys live in managed secret stores and are never committed to source code.

Payments and email

Card data is handled by Stripe and never touches our servers — payment details are collected directly by Stripe under its PCI-DSS Level 1 program. Transactional and outreach email is sent through Resend, with per-workspace sending domains so your mail is authenticated as coming from you, kept separate from every other customer.

The full list of services that process customer data is published on our subprocessors page.

Your data rights

You stay in control of your data. Chuhching supports GDPR-style data access and erasure: you can export your data in one click, and you can delete it. Our Privacy Policy and Data Processing Agreement describe how we handle personal data on your behalf.

On our roadmap

The items below are planned or in progress — they are commitments we are working toward, not capabilities we claim to have completed today.

  • SOC 2 Type I (planned) — an independent report on the design of our security controls.
  • Security disclosure policy (planned) — a dedicated security@chuhching.com contact and a 90-day coordinated-disclosure window for researchers who report vulnerabilities responsibly.
  • Status page (planned) — public visibility into uptime and incident history.

Questions

Security or privacy questions? Email privacy@chuhching.com. For legal questions, email legal@chuhching.com.