Security
Last updated: August 2026
Encryption
- In transit: all traffic to GWC services runs over TLS with a modern certificate chain.
- At rest: provider credentials, OAuth tokens, and credentials retained solely for historical settlement are encrypted with AES-256-GCM. Conversation and workspace data is stored on GWC's own servers under authenticated per-account access control; it is not separately encrypted at the application layer.
- On your machine: Taichu manages local credential storage. Protection depends on the platform and installation; local encryption keys may be held in files with restricted access.
Your API Keys (BYOK)
- Bring-Your-Own-Key keys are never stored on GWC servers. They remain on your device, where the local runtime can retain them in protected storage and use them to authenticate requests to your provider.
Agent Execution Safety
- Every disruptive action an AI agent attempts (shell commands, file writes) passes a policy engine and approval gate before it runs.
- Isolation depends on the runtime configuration and supported backends. Without a configured sandbox, commands run on the host under the approval gate above. Sandbox setup for the extension release is still being verified.
- Agent roles run under least-privilege tool envelopes — a reviewing role structurally cannot modify what it reviews; a measuring role structurally cannot alter what it measures.
Your Data
- We never use your code or conversations to train AI models.
- We don't sell your data. Service providers process data as described in our Privacy Policy.
Certifications
- GWC does not currently hold SOC 2 or ISO 27001 certification. We state this plainly rather than implying otherwise; the controls above are real and verifiable in the product.
- Security questions: support@gwc-corp.com