About EntryDesk Security

EntryDesk provides enterprise-grade security for AI teammate deployments. Key security features include: Role-Based Access Control (RBAC) for managing user permissions across workspaces; BYOK (Bring Your Own Keys) allowing organizations to use their own LLM API keys — keys are never stored in plaintext; comprehensive audit logs tracking all AI actions; Tool Approval giving IT control over which connectors AI can access; Resource Governance with progressive publishing (Personal → Team → Workspace) to prevent unvetted tools from spreading; OAuth 2.0 connector authentication with per-user tokens (no shared service accounts); SSO via SAML on the Enterprise plan; and SOC 2 Type II compliance (in progress). EntryDesk supports multiple LLMs (Claude, GPT, Gemini) and never trains models on customer data. Prompt content is processed in-memory and not persisted by default.

SOC 2 Type II in progress

Security your IT team
will actually approve.

Enterprise-grade controls for your AI.

Your data stays yours

EntryDesk never trains on customer data. LLM providers receive only what's needed for each task.

IT stays in control

RBAC, Tool Approval, and audit logs give your IT team full visibility and governance.

Bring your own keys

Use your organization's own LLM API keys. Your model, your terms, your data residency.

Security features built for
real-world governance.

Role-Based Access Control (RBAC)

Assign roles at workspace, team, and user levels. Control who can create agents, connect tools, and publish resources. Permissions follow your org structure.

Tool Approval

IT admins approve which connector tools AI teammates can access. Block sensitive operations, allow read-only access, or approve full automation per tool.

Audit Logs

Every AI action is logged: which user triggered it, what tools were accessed, what data was read or modified. Full audit trail for compliance.

BYOK (Bring Your Own Keys)

Enterprise customers can use their own LLM API keys from OpenAI, Anthropic, or Google. Your data goes through your own provider agreement.

OAuth Connector Auth

All third-party integrations use OAuth 2.0. No passwords stored. Users authorize each connection individually. Revoke anytime.

Resource Governance

Progressive publishing: Personal → Team → Workspace. Agents and skills start private. Only promoted resources are visible to the broader team, preventing unvetted tools from spreading.

Multi-LLM Architecture

Switch between Claude, GPT, and Gemini at any time. No vendor lock-in. When a better model arrives, your agents and workflows keep working.

Secure Authentication

All connector authentications use OAuth 2.0 with per-user tokens. Each team member authenticates with their own credentials — no shared service accounts.

How your data flows

Your Tools
OAuth-authenticated
EntryDesk
Orchestration Layer
Encrypted in transit (TLS 1.3)
LLM Provider
Task-scoped data only

EntryDesk acts as an orchestration layer. Only the data relevant to each task is sent to the LLM. No persistent storage of conversation data beyond your configured retention period.

1

User sends a request

Through the EntryDesk web interface or Slack/Teams chatbot.

2

EntryDesk routes to the right model

Using your BYOK API key or EntryDesk-managed keys. Your prompt is sent to the LLM provider (OpenAI, Anthropic, Google) — EntryDesk does not store prompt content.

3

Agent executes via approved connectors

If the task requires tool access (e.g., read Salesforce, write to Slack), the agent uses the user’s own OAuth token. Only IT-approved connectors are available.

4

Results returned to user

Output is displayed in the conversation. Audit log records the action, the user, and the connector used.

Compliance & certifications

SOC 2 Type II

In progress (expected Q3 2026)

In progress

GDPR Compliant

EU data handling ready

Compliant

TLS 1.3

All data encrypted in transit

Active

No Model Training

Contractually guaranteed

Guaranteed

Frequently asked questions

Does EntryDesk store our data?

EntryDesk stores conversation metadata (timestamps, user IDs) for the audit log. Prompt content and tool responses are processed in-memory and not persisted by default. With BYOK, all LLM calls go directly through your provider account.

Can we restrict which tools agents can access?

Yes. Tool Approval lets IT admins whitelist specific connectors. Users can only connect to approved tools. New connector requests go through an approval workflow.

How does BYOK work?

You add your own API keys for OpenAI, Anthropic, or Google in the workspace settings. All LLM calls use your keys and are billed to your accounts. EntryDesk never sees or stores your API keys in plaintext.

Can we see what agents are doing?

Audit logs track every agent action: which user triggered it, which connector was used, what action was taken, and when. Logs are exportable for compliance reviews.

What happens if an LLM provider goes down?

EntryDesk supports multiple LLMs. You can switch providers without rebuilding agents or workflows. Your configuration, connectors, and automations remain intact.

Do you support SSO?

SSO via SAML is available on the Enterprise plan. Contact our team for details.

Is EntryDesk SOC 2 certified?

SOC 2 Type II audit is in progress, expected Q3 2026. We are happy to share our current security documentation and practices upon request.

Have security questions?

Our team is happy to walk through EntryDesk's security architecture with your IT department.

Talk to Our Team  →
Free plan available · Enterprise SSO via SAML