Your data, your accounts, your machine.
Writ automates the sites you already log in to - with your credentials encrypted at rest, injected only at run time, and never returned, shown to AI, or logged.
Trust you can verify, not just claim
Four principles cover how Writ protects your credentials, keeps tenants apart, honors your data rights, and keeps automation to sites you are authorized to use.
Credentials injected at run time - never exposed
Every sensitive value is encrypted at rest with the platform key and resolves to a real value only inside a single run. Nothing sensitive is ever returned, shown to AI, or logged.
What is encrypted
- Persona passwords and 2FA (TOTP) seeds
- Vault secrets, mailbox tokens, magic-link credentials
- Network egress credentials you supply
- Saved warm auth sessions (cookies, storage, headers)
How keys and tokens work
- Secrets are Fernet-encrypted at rest with the platform key
- Secret references resolve to real values only inside a single run
- API keys are prefixed
wt_ - OAuth tokens
wto_are Argon2-hashed, scoped, and revocable
Never returned. Secrets are never returned through the API, shown to the AI navigation model, or written to logs. The non-secret login identifier is visible so you can tell accounts apart; nothing sensitive is. See the secrets vault and personas.
On local runs, your data never leaves your machine
Writ runs on your own hardware by default. Nothing is sent anywhere, your AI keys stay local, and there is no compute charge. Move to the managed cloud only when you want to.
Run on your machine
Pages, extracted data, credentials, and AI keys stay on your device. Reach intranet-only systems, and pay nothing for compute - BYO-AI runs are unbilled.
Or run in the managed cloud
When you need scheduling and scale, the managed cloud fleet runs it, metered by running time from your prepaid balance beyond the included usage.
You choose the venue per workflow. Learn how venues are picked on the agents page.
One tenant can never read another's data
Every record is scoped to an organization's tenant ID and filtered at the data layer. Isolation is the default, not a setting you turn on.
Workflows, monitors, personas, secrets, agents, runs, and the wallet are all tenant-scoped and filtered at the data layer. The same boundary governs the marketplace and BYO-agent routing: installs run in your tenant, on your data, and sensitive runs (logins, secrets) are never routed to a foreign machine.
Tenant-scoped at the data layer
No cross-tenant reads. No cross-tenant routing of sensitive runs.
You choose where sensitive runs execute
Local, managed cloud, or a hardened sandbox - sensitive material is never routed to another tenant's machine.
The rule. Sensitive material (credentials, secrets, persona logins) is never routed to another tenant's machine. Learn how venues are chosen on the agents page.
Install a workflow - never someone else's credentials
Workflows installed from the marketplace are recipes only: steps and a manifest of the inputs they need. Every run uses the installer's own data.
Creator side
A creator's personas, credentials, secrets, and sessions are stripped at publish and never used on anyone else's run. A literal embedded secret blocks publish until it's parameterized.
Install side
Whoever installs attaches their own personas, secrets, and inputs. Runs resolve only the installer's tenant data - the cross-tenant path is install and run, never sharing credentials.
Authentication & MFA
Protect your account with multi-factor authentication, rotating sessions, and lockout on repeated failures.
Connect or disconnect social sign-in from Settings. See the authentication docs.
You own your data - export or delete it anytime
Export your data, or delete your account or organization, from Settings. Deletion cascades across every tenant-scoped resource, GDPR-aligned, with a DPA available.
Authorized automation, enforced
Writ is for your own accounts, your own data, and sites you have the right to access - and we build the guardrails to keep it that way.
We publish an Acceptable Use Policy, enforce a domain blocklist at every URL choke-point, and run live anomaly and abuse monitoring. Responsible use protects the whole platform - and it's a feature, not fine print.
Found a vulnerability? Tell us - you have our safe harbor
We welcome good-faith security research and follow a coordinated-disclosure model. This is the policy referenced by our security.txt; report privately and give us reasonable time to fix before going public.
How to report
Email security@usewrit.app - a PGP key is available on request; encrypt anything sensitive. Please do not open a public issue, post to social media, or disclose the finding to anyone else until we have coordinated a fix.
Email the security teamPlease include
- A clear description of the issue and its impact
- Steps to reproduce, or a minimal proof-of-concept
- Affected URL, endpoint, or component
- Never real credentials, secrets, or another tenant's data - redact them
Safe harbor - no legal action We will not pursue or support legal action against good-faith research that follows this policy. Activity consistent with it is considered authorized; if you are unsure whether something is in scope, ask first at security@usewrit.app before proceeding.
- Respect the disclosure process and give us reasonable time to fix before going public
- Only access your own account and data - never another tenant's
- Do not exfiltrate data beyond the minimum needed to demonstrate the issue
- Do not degrade service, run automated volumetric or DoS testing, or violate privacy or applicable law
In scope
- The Writ Cloud web app, API, and marketplace
- usewrit.app and its authenticated product surfaces
- Authentication, session, MFA, and account-security flaws
- Tenant-isolation, access-control, and secret-handling issues
Out of scope
- Denial-of-service, volumetric, or automated load testing
- Social engineering, phishing, or physical attacks on staff
- Reports from automated scanners with no demonstrated impact
- Third-party services and sub-processors - report those to their own programs
Response targets
Best-effort targets under coordinated disclosure - not a contractual SLA. If we cannot meet one, we will tell you and keep you updated.
| Stage | Target |
|---|---|
| Acknowledge receipt | within 3 business days |
| Triage and severity assessment | within 10 business days |
| Fix or mitigation plan for High / Critical | within 30 days |
| Public disclosure | coordinated - after a fix ships or 90 days, whichever comes first |
We credit reporters in our advisories unless you ask to remain anonymous. There is no paid bug-bounty program at launch - intake is coordinated disclosure with safe harbor. A bounty may be introduced later; this section is authoritative until then.
Compliance
We build to recognized security and privacy standards and align our controls with GDPR - with a signed DPA, data-erasure tooling, and documented sub-processors. We don't claim certifications we don't hold. For a current security review or DPA, contact us.
Single sign-on
SSO and audit features are available for larger teams. Talk to us about your requirements.
Security questions, answered
Where do my credentials and secrets live?
Does my data ever leave my machine?
Can one organization see another organization's data?
What is your compliance posture?
Can I export or delete my data?
See exactly how Writ protects your data.
Start on your own machine, on your own accounts, with your own data.