ProcedureDeterministic AgentsMarketplaceSecurity
Book a Demo
ProcedureDeterministic AgentsMarketplaceSecurity
Book a Demo
GDPRNISTSOC 2ISO 27001Coming soon

Security

Built for work you cannot afford to get wrong

Isolated execution, credentials that stay in your vault, access scoped by role, and a record of every run.

View Trust CenterBook a Demo

Isolated execution

Every run starts in an isolated environment

Stepwork keeps automated work separated from the browser sessions and applications your team uses every day.

A machine in your environment

Flows execute in an isolated browser container on a machine in your environment. Nothing runs directly against a user’s everyday browser session.

A container in the Stepwork cloud

Cloud containers provide an isolated environment for scheduled and unattended work without depending on a local machine being awake.

Credential protection

Your credentials and keys stay protected

Stepwork keeps credentials, identity connections, and API keys protected throughout every run. Secrets are retrieved only when needed, encrypted at rest, and never exposed to Stepwork employees.

How credentials and secrets are handled

  • Credentials are retrieved only when a flow runs
  • Passwords are never pasted into procedure variables
  • Existing sign-in methods and identity providers, including Okta, remain in place
  • API keys are encrypted and managed through AWS KMS, with no employee access
  • Okta
  • 1Password
  • API secrets

Security controls

Control who can act, what can run, and what gets recorded

Connect Stepwork to your existing identity systems, define access by role, require approval for sensitive steps, and maintain a complete record of every run.

A complete record of every run

Each run records the steps taken, the outcome, any failure reason, who triggered it, and whether it ran manually or on a schedule. If a step fails, the record shows exactly where the process stopped and why.

Role-based access

Administrators, managers, and members can configure, manage, and run different parts of Stepwork based on their responsibilities.

Organization isolation

Data, flows, Procedures, and run records remain scoped to the customer’s organization.

Secure API key storage

API keys are encrypted at rest with AWS Key Management Service. Keys are decrypted only when a flow needs them, and Stepwork staff cannot read stored key values.

Use your existing identity system

Single sign-on connects Stepwork to the identity provider your organization already uses.

Require approval for sensitive steps

Selected steps can pause for review by a named approver. The run continues after approval, and the decision is recorded in the run history.

Share diagnostic data only when needed

Detailed logs and diagnostic data remain off by default. Administrators can enable sharing when they need Stepwork’s help investigating a failed run.

Privacy and compliance

Security documentation, ready when your team needs it

Review Stepwork’s current security practices, compliance information, and available documentation through the Trust Center.

View Trust CenterContact the security team
Stepwork

Deterministic agents for work that must run
the same way every time.

Terms and ConditionsPrivacy PolicyData Processing AgreementSubprocessors

1849 Union St, San Francisco, CA 94123, USA

Loot Discount inc dba Stepwork

© 2026 Stepwork. All rights reserved.