Bleenk logo

Trust Center

Security at Bleenk

How Bleenk Studio isolates workspaces, protects credentials, routes AI requests, and supports security reviews.

Data access

Role-based (team & project)

Workspace isolation

Per-project sandboxes

Customer API keys

BYOK on paid plans

Overview

Bleenk Studio helps teams build, run, and deploy full-stack apps with AI agents in isolated dev environments. We process account and billing data, project source code, chat and agent logs, encrypted credentials, and deployment settings. Production runs on Kubernetes on AWS with per-project namespaces and network policies, plus PostgreSQL, Redis, and object storage. We protect data with TLS, Fernet encryption for secrets and OAuth tokens, scoped agent tools with approval gates, and team audit logs.

security@bleenk.app·Privacy Policy

Compliance

Framework alignment for procurement. Audit reports available on request where applicable.

Resources

Request access for gated documents (mailto security@bleenk.app).

Controls

View all

Infrastructure security

  • Per-project isolated sandboxes (Kubernetes namespaces with network policies; Docker isolation in local dev)
  • Encryption in transit via HTTPS/TLS for production traffic; optional TLS for PostgreSQL
  • Fernet encryption at rest for deployment OAuth tokens, channel credentials, BYOK keys, and project secrets
  • Network policies restrict ingress and egress between platform services and project workspaces
Learn more

Organizational security

  • Team RBAC with admin, editor, and viewer roles
  • Team and project audit logs with CSV export for workspace admins
  • Optional email 2FA and WebAuthn passkeys for login
  • Email domain allowlist and blocklist for signup compliance

Product security

  • Agent approval gates in Ask mode and pause-for-approval for risky tool calls
  • In-product security scanning with compliance framework labels
  • Command, pod access, and workspace audit logging; CSRF protection and security headers on APIs
  • Rate limiting on sensitive endpoints (for example secret reveal and 2FA)
Learn more

AI security

  • Model routing through a LiteLLM proxy to upstream providers
  • BYOK on paid plans (Basic, Pro, Ultra): encrypted customer keys billed without platform credits when active
  • Project secrets scoped to approved shell execution with output scrubbing
  • Tool-scope gating; dangerous tools require explicit user approval in Ask mode
Learn more

Network security

  • Kubernetes network policies for platform services and project compute namespaces
  • Internal API routes authenticated for cluster-internal callers
  • CORS and CSRF middleware with secure cookie settings
  • Per-container preview hostnames with TLS via ingress in production

Internal security practices

  • Structured audit tables for team actions, agent commands, and pod access
  • Non-blocking background jobs for deploy, snapshots, and agent work
  • Contact security@bleenk.app for incident response and operational security program details

Data collected

Data categories Bleenk Studio stores or processes for cloud customers. We do not store payment card numbers on Bleenk servers.

  • Customer account dataYes
  • Source code and project contentYes
  • Chat, agent steps, and command audit logsYes
  • Encrypted API keys and integration tokens (BYOK, Git, deploy providers, MCP, channels)Yes
  • Billing and subscription metadata (via Stripe)Yes
  • Optional product analytics (PostHog, when configured)Yes
  • Employee account data (Bleenk staff)Yes
  • Payment card dataNo
  • Personal health informationNo

Subprocessors

Third parties that process customer data for hosted Bleenk Studio, plus providers customers connect on their own. Regions reflect typical deployment. Confirm current hosting with security@bleenk.app for contracts.

  • Amazon Web Services (AWS)

    Production Kubernetes (EKS), container registry (ECR), object storage (S3), and related cloud infrastructure.

    Regions
    US

  • PostgreSQL database provider

    Platform database (managed PostgreSQL / RDS or hosted Postgres per environment).

    Regions
    US, EU (per deployment)

  • Redis

    Task queue, pub/sub, streams, caching, and rate limiting.

    Regions
    US (in-cluster or managed per deployment)

  • LiteLLM / AI model providers

    LLM API routing; upstream providers include OpenAI, Anthropic, OpenRouter, Groq, Together, DeepSeek, Fireworks, and others configured in the catalog or via customer BYOK keys.

    Regions
    US, Global (provider-dependent)

  • Stripe

    Subscriptions, checkout, and billing webhooks; card data stays with Stripe.

    Regions
    US

  • Resend (or SMTP)

    Transactional email (2FA codes, password reset, invites) when configured.

    Regions
    US

  • Cloudflare

    DNS, TLS, and optional Workers/Pages deployments when customers connect Cloudflare or when the platform uses Cloudflare for certificates.

    Regions
    US, Global

  • GitHub / GitLab / Bitbucket

    Repository access when customers connect version control (OAuth tokens encrypted at rest).

    Regions
    US, EU

  • Deployment platforms (customer-authorized)

    Vercel, Netlify, Cloudflare, Heroku, DigitalOcean, and similar targets when customers deploy from Studio.

    Regions
    US, EU, Global

  • Web search (platform-configured)

    Tavily, Brave Search, or DuckDuckGo when agent web search uses platform API keys.

    Regions
    US

  • PostHog (optional)

    Frontend product analytics when configured; respects Do Not Track in client initialization.

    Regions
    US, EU (PostHog project configuration)

FAQ

Where can I find Bleenk security documentation?
Product security practices are summarized on this Trust Center and in public docs at https://docs.bleenk.app. Enterprise customers can request architecture diagrams, a subprocessors list, and completed questionnaires by emailing security@bleenk.app.
How does Bleenk handle AI and customer data?
Agent prompts and project context are sent to the model path you use: Bleenk’s LiteLLM proxy for built-in models or your own provider keys on paid plans (BYOK). User and project API keys are encrypted at rest. Agents inspect secret key names in project config but do not receive plaintext secret values through config tools; shell tools that need secrets use scoped execution with output scrubbing. Risky agent actions can require explicit approval in Ask mode or via tool contracts.
Do you offer a Data Processing Agreement (DPA)?
Enterprise customers can request a DPA during procurement. Contact security@bleenk.app to start a review.
What is your incident response process?
Report suspected vulnerabilities or incidents to security@bleenk.app. Customer notification practices are shared during enterprise onboarding.
Do you support SSO, SCIM, or HIPAA BAA?
Enterprise SSO/SAML and SCIM are on the product roadmap. Login today supports email/password, OAuth (Google/GitHub), optional email 2FA, and passkeys. HIPAA BAA availability is on request. Contact security@bleenk.app.
Where is production hosted? Can we use BYOK?
Hosted Bleenk Studio is multi-tenant on Kubernetes (AWS EKS in production), with per-project isolation. BYOK is available on paid tiers (Basic, Pro, Premium/Ultra): customers store provider API keys encrypted in Bleenk and requests route directly to those providers without consuming platform AI credits.

Updates

View all