Trust & security
Security
RedCell is built for authorized security testing and defense, so we hold ourselves to the standard we help our users enforce. Here is how the product handles execution, scope safety, data, and access.
Last updated: July 24, 2026
Scope guardrails & responsible testing
RedCell is built strictly for authorized security testing. Every action passes through an integrated scope-guard that verifies target authorization and confirms rules of engagement before proceeding. Out-of-scope traffic, rate-limit violations, and destructive activity are blocked by hardened safety policies.
Host-local execution
The agent runs on the operator's own machine. Your files, logs, and the commands RedCell runs stay local — they are read and written on your host and are never uploaded to us. RedCell operates against the systems and data you are already responsible for defending.
Data handling
Only the model turns needed for reasoning are sent to the inference backend. Provider data-retention is set to deny, so prompts are not retained by the inference provider for training or storage.
We record usage metadata — such as token counts, the model used, and timestamps — to meter your account and operate the service. Prompt and file content is not stored beyond lightweight session aggregates needed to run and resume your work.
Token security
Bearer tokens are stored sha256-hashed — we never keep the plaintext value. Every token is revocable from the console the moment a device is lost or rotated, and CLI logins carry a 30-day expiry so idle devices lose access automatically.
Responsible disclosure
Found a vulnerability? We want to hear from you. Email [email protected] with the details and steps to reproduce, and please give us a reasonable window to remediate before any public disclosure.
This page is a template provided for reference and does not constitute legal or security advice. Review it with qualified legal counsel and your security team before launch.