Our Founders kept the world's critical systems safe. Agents are the next frontier, and they need the same discipline.

Healthcare, education, the Fortune 2000: the same obsession with least privilege, auditability, and never touching data we shouldn't. OneBee runs AI agents inside your real systems, so we build them the way we built defenses: privacy-first, from the ground up.

Runs exclusively on GCPNever trains on your dataSOC 2 in progressCCPADPA available

Seven commitments we engineer for.

Not aspirations, just the controls and defaults the platform is built around.

We never train on your data

By contract

Full stop. Your data is used only to run the agents you've asked for, never to train models, ours or anyone else's. It's written into every contract, and it's core to our DNA.

in every contract
Enforced

A complete agent paper trail

Every agent action is logged (tool calls, sub-agent calls, and inter-agent messages) for an attributable, auditable record of exactly what ran, when, and why.

tool · sub-agent · message logs
On by default

Least-privilege by allow-list

Every agent runs against an explicit tool allow-list: only the specific actions a task needs, scoped to single systems, and revocable in one click.

allow-list · 1-click revoke
Server-enforced

Access control and tenant isolation

Role-based permissions decide which people, teams, and agents reach which systems and data. Each tenant's storage is separately scoped, so one customer's data is unreachable from another.

15 permissions · per-tenant scoping
Enforceable

Human-in-the-loop, enforceable

Approval can be required on every agent action. You decide what an agent may do on its own, and what always waits for a person.

per-action approval gates
Public list

Few, vetted subprocessors

A short, public list of providers, none of which use your data to train their models. We notify you before the list changes.

notified before any change
Always on

Encrypted in transit & at rest

TLS 1.2+ in transit, AES-256 at rest. Secrets and tokens live in a dedicated, access-controlled vault, never in plain sight.

TLS 1.2+ · AES-256

One home. A short, named supply chain.

No mystery infrastructure. Your agents and data live in Google Cloud; everything else is a small set of vetted providers, each doing one job.

Google Cloud

Google Cloud Platform

The Hive, OneBee's managed-agent platform, runs exclusively in GCP: your agents, your data, and the platform itself.

Production home

Vetted subprocessors: none train on your data

Google Cloud PlatformHosting and infrastructure; the platform, agents and data run here
Microsoft AzureFrontier models; no training on your data
CloudflareEdge network, DDoS protection & WAF
AnthropicFrontier models; no training on your data
OpenAIFrontier models; no training on your data
xAIFrontier models; no training on your data
BasetenOpen-weight model inference
Fireworks AIOpen-weight model inference
Brave SearchIndependent web search; no training on queries
ResendTransactional email delivery
+Always currentWe notify you before this list changes

The contractual Sub-processor List, with each provider's processing location and retention, is Annex 3 of the Data Processing Addendum.

Isolation by design. Each agent reaches a provider only through its scoped allow-list, and only for the task at hand. No provider gets standing access to your environment, your credentials, or your data.

What your data powers, and what it never will.

What your data powers
  • Running the specific agents and tasks you've approved
  • Tuning your agents for your workflows
  • Monitoring for drift, errors, and anomalies
  • The audit log you can inspect and export
What we'll never do
  • Train models, ours or anyone's, on your data
  • Sell, rent, or share your data with advertisers
  • Let subprocessors train on or learn from your data
  • Give agents standing access beyond their allow-list

Evaluating us? Here's what we'll hand over.

We've sat on your side of the vendor review. Ask and we'll provide:

  • Completed security questionnaires
  • Architecture & data-flow diagrams
  • Our DPA, incorporated by reference
  • Infrastructure provider certifications
  • Direct line to our security team