Security
Security overview
How Inhaus keeps AI-built apps and company data safe.
AI tools write working apps fast. They also write API keys into code, send data to sites nobody checked, and skip the login. Inhaus puts a layer around every app so those mistakes do not reach your team or your customers.
The gateway checks sign-in and permissions before any request reaches the app. The app never handles passwords.
Fixed rules plus an AI review look for leaked keys, data leaving the company and unsafe code.
The scan lists every website an app sends data to. One your admin has not approved blocks the app from the directory.
An app reaches the whole company through the company directory. It needs a scan with no blocking issues, and an admin's approval if your policy asks for one.
Each app runs on its own, with its own database role, file storage and secrets. One app cannot read another's data.
Every open, share, deploy, export and blocked request is recorded.
Where your data lives
| What | Where |
|---|---|
| Inhaus accounts, apps, permissions and the access log | PostgreSQL on AWS, us-east-2 (Ohio) |
| App databases | One PostgreSQL schema and role per app, on AWS in the same region |
| App files | Private object storage on AWS. Only reachable through short-lived signed links |
| Secrets | AWS Secrets Manager, encrypted, one secret per app |
| Running apps | Isolated JavaScript sandboxes on Cloudflare's network |
Sign-in
- People sign in to Inhaus with Google, Microsoft or a one-time email link.
- People open apps by signing in with their company Google or Microsoft account. The app itself never sees a password.
- The dashboard and every app have separate sessions. Signing out of the dashboard does not keep an app session alive on another device, and removing someone's access locks them out of the app within about 30 seconds.
Report a security issue
Email [email protected] with "Security" in the subject.