Security
Effective 24 September 2026 · Slobal, Ireland
This page states plainly what Slobal products store, what they do not, and where the data that does reach us is held. For the legal detail behind each point, and your rights over the data, see the privacy policy.
What we store
- Account data · email address, display name, and a salted hash of your password.
- Workspace and billing records · workspace name, company name, licence and order state. Card details are held by Stripe, not by us.
- Hosted instance content, on the cloud tiers only · if you run a Helmsly instance on a Slobal-hosted cloud tier, we hold what that instance holds: its sessions, memory and files, in a container and volume of its own.
- AgnCred evidence · signed receipts, cryptographic hashes and attestations about agent work. Not the private content behind that work.
- Service logs · IP addresses and request metadata, kept briefly for rate limiting and incident response.
What we do not store
- On the local and relay tiers, Helmsly runs on your own machine. What your agents read, write and remember stays there. We never receive it.
- AgnCred records work by cryptographic hash and attestation. The private content behind a receipt does not reach AgnCred. Only fingerprints, hashes and metadata are submitted for scoring and verification.
- We hold no card numbers. Stripe processes and stores payment details on our behalf.
- We run no analytics, advertising or tracking scripts on slobal.com.
Where data sits
Everything Slobal processes runs on infrastructure in the EU. A Helmsly instance we host for you also runs in the EU: the hosting layer does not offer a region outside it.
Subprocessors
The full list, with data, region and a dated change log, is at slobal.com/subprocessors. The data processing agreement sets the terms.
- Contabo
- Hosting for slobal.com, sign-in, the relay and our databases.
- Cloudflare
- DNS, CDN and security proxying for slobal.com.
- Resend
- Delivery of transactional email: sign-in, account and order messages.
- Stripe
- Payments for licence orders.
- Microsoft 365
- Company mail, including support correspondence.
- GitHub
- Code hosting for our own software and documents. No customer content.
Retention
- Account and workspace data
- Life of the account
- Hosted instance after a licence lapses
- 30 days, then the volume and its key are destroyed
- Dormant personal accounts
- Two years, then deleted
- Inactive AgnCred records
- Two years of no activity, then erased
- Order and billing records
- Six years, under Irish tax law
- Service logs
- Up to 30 days
The full retention rules, including how each period is enforced, are in the privacy policy.
Account controls
- Two-step verification is available on every account.
- The sign-in session is a single strictly necessary cookie, HttpOnly and Secure, that lasts up to 30 days, or until you sign out.
- You can ask for an export or deletion of your data at any time. See the your rights section of the privacy policy.
Report a security issue
Write to support@slobal.com, or see security.txt for the reporting contact and preferred format. A person reads and answers every report.