Security

Security controls you can inspect.

Skrum combines vetted identity, encrypted secret storage, explicit consent, and permission checks. The documentation explains each boundary.

Better Auth owns identity

Sessions, password hashing, verification, reset, OAuth, and two-factor flows stay in a vetted authentication library.

Read the guide

AES-256-GCM secret envelopes

AI keys and integration secrets are encrypted at rest with a master key that never enters the client bundle.

Read the guide

Consent-gated recordings

Recording is explicit and join flows require acknowledgement when a meeting requires recording consent.

Read the guide

Bring-your-own-key handling

Workspace provider keys are encrypted, hint-only in responses, and omitted from prompts, logs, and usage telemetry.

Read the guide

Workspace and project isolation

Product routes resolve workspace membership and resource visibility; foreign resources return 404 rather than revealing existence.

Read the guide

Enterprise identity controls

Eligible plans add SAML or OIDC SSO, SCIM provisioning, session controls, two-factor policy, and IP allowlists.

Read the guide

Open security.txt for responsible disclosure

Bring delivery into one workspace

Start your free workspace →

See managed plans, explicit caps, and credit packs on the pricing page.