Security

Security overview

How Inhaus keeps AI-built apps and company data safe.

AI tools write working apps fast. They also write API keys into code, send data to sites nobody checked, and skip the login. Inhaus puts a layer around every app so those mistakes do not reach your team or your customers.

Where your data lives

WhatWhere
Inhaus accounts, apps, permissions and the access logPostgreSQL on AWS, us-east-2 (Ohio)
App databasesOne PostgreSQL schema and role per app, on AWS in the same region
App filesPrivate object storage on AWS. Only reachable through short-lived signed links
SecretsAWS Secrets Manager, encrypted, one secret per app
Running appsIsolated JavaScript sandboxes on Cloudflare's network

Sign-in

  • People sign in to Inhaus with Google, Microsoft or a one-time email link.
  • People open apps by signing in with their company Google or Microsoft account. The app itself never sees a password.
  • The dashboard and every app have separate sessions. Signing out of the dashboard does not keep an app session alive on another device, and removing someone's access locks them out of the app within about 30 seconds.

Report a security issue

Email [email protected] with "Security" in the subject.