Security

Security controls you can inspect.

Skrum combines vetted identity, encrypted secret storage, explicit consent, and permission checks. The documentation explains each boundary.

  • Every AI action human-approved
  • Bring your own AI keys
  • 7 languages, RTL included

Better Auth owns identity

Sessions, password hashing, verification, reset, OAuth, and two-factor flows stay in a vetted authentication library.

Read the guide

AES-256-GCM secret envelopes

AI keys and integration secrets are encrypted at rest with a master key that never enters the client bundle.

Read the guide

Consent-gated recordings

Recording is explicit and join flows require acknowledgement when a meeting requires recording consent.

Read the guide

Bring-your-own-key handling

Workspace provider keys are encrypted, hint-only in responses, and omitted from prompts, logs, and usage telemetry.

Read the guide

Workspace and project isolation

Product routes resolve workspace membership and resource visibility; foreign resources return 404 rather than revealing existence.

Read the guide

Enterprise identity controls

Eligible plans add SAML or OIDC SSO, SCIM provisioning, session controls, two-factor policy, and IP allowlists.

Read the guide

Open security.txt for responsible disclosure

Bring delivery into one workspace

Start your free workspace →

See managed plans, explicit caps, and credit packs on the pricing page.