Trust, stated plainly
What actually protects your work
No badges we didn't earn. Here is exactly what the platform enforces today — and, just as plainly, what we haven't built yet.
Built and enforced today
Money approval gates
Anything that moves money — a charge, a refund, a payout, real ad spend — pauses for a human to approve or reject, with the exact amount shown. Everything else the fleet ships on its own.
Tenant isolation
Every request is scoped to your workspace. One tenant can never read or touch another's data, sessions, or secrets.
Kill switch
One switch halts all autonomous launches for a workspace immediately — no in-flight work can start once it's flipped.
Budget caps
Per-tenant spend and concurrency ceilings stop a runaway fleet before it bills you, not after.
Append-only audit trail
Every approval and every blocked egress is written once and never edited, so the record can't drift from what happened.
Per-agent scoped credentials
Each agent only ever receives the secrets its job needs. The research agent reads its crawl token and never your payment keys.
Egress allowlists
When you enable it, agent sessions can only reach the domains you list; anything else is denied and flagged to the audit trail.
Roles for your team
Owners, approvers, and viewers. Only approvers clear approvals; viewers look but can't touch.
On the roadmap — not yet
SOC 2 Type II
Planned — not yet certifiedWe're building toward an audit. We are not certified today and don't claim to be.
SSO / SAML
Designed seam — not yet builtThe wiring point exists in the code; no identity provider is connected yet.
Kernel-level network policy
Partial — application-enforced todayEgress is enforced at the application layer now; in-sandbox kernel enforcement is the next step.
Support SLA
We acknowledge customer support requests within one business day. Billing, access, and live-work blockers are prioritized first, and every support case keeps an auditable status instead of disappearing into email.
Production readiness, without the fog machine
If you are putting real marketing work through ipop, these are the controls to inspect before trusting autonomy.
External proof lane
Dogfood receipts, consent-pending customer outcomes, and independently validated customer proof are tracked separately. If a customer has not approved publication, the public surface says so instead of borrowing the metric.
Policy setup and dry-runs
Workspace policy is configured through approval policies and scoped connection settings. Teams should test a proposed policy in dry-run before enabling live sends, spend, publishing, or deploys.
Readable decisions and rollback
Allowed, blocked, failed, and rolled-back actions need receipts a human can read: who requested it, which policy matched, what changed, what evidence came back, and what rollback path exists.
Setup and permission docs
Production onboarding needs the integration, permission, credential, rollback, and failure-mode docs in front of the buyer before they hand agents live accounts.
What we don't claim
We hold no third-party security certifications today. This page describes mechanisms we built, not audits we passed. When that changes, this page will say so — with a date.
Back to home