Security
Reminix runs code your team wrote, with your API keys. Here is how it keeps both safe. If your security team has a questionnaire, send it to security@reminix.com.
Where your code runs
Each version of a script runs in its own isolated sandbox. It can't reach other scripts, your workspace's data, or Reminix itself; it sees only its inputs. It has no network access unless its version lists the hosts it may call, and then it can reach only those, over HTTPS, with every request written to the run's log. A run has a time limit, and a long run can be cancelled.
Secrets
Reminix encrypts API keys at rest (AES-256-GCM, with a key per workspace). They're write-only: once you save one, nothing shows the value again, not the app, the API, the command line or an agent. Reminix attaches a secret to a request only when the request goes to a host that secret allows, so the code doesn't hold it. Code can read a secret only if its owner turns that on.
Who can do what
- You share each script with the whole workspace or only with chosen teams. Others don't see it at all.
- A script can require a person's approval for runs started by AI agents, or for every run.
- Nothing goes live until its owner, or a workspace owner or admin, publishes it. An agent's publish always waits for a person, and a workspace can require a second person for every publish.
- Only owners and admins can save or change secrets. Agents can list them, but never save, change or read them.
What Reminix stores
Your account and workspace details; each script's code, versions and settings; and every run: its inputs, output, log, and who started it from where. Reminix keeps run logs for your plan's period (7, 30 or 90 days), and keeps each run's record while the workspace exists.
Where it's stored
Code runs on Cloudflare's network. Reminix keeps script code and run logs in object storage (Cloudflare R2). It keeps accounts, settings and run records in a managed PostgreSQL database (Neon) in a single region, with the provider's point-in-time recovery for backups. We encrypt all traffic in transit (TLS 1.2 or later, with HSTS), and data at rest.
Signing in
People sign in with an email and password, checked against known breaches, and can turn on two-factor authentication. We store only hashes of passwords, API keys and personal access tokens. We show a key or token once, when you create it, and each carries scopes. Our own staff must use a verified address and two-factor authentication to reach customer data, and we record every staff action on customer data.
Audit log
Reminix records these in an append-only log that workspace owners can read: membership changes, script access and approval settings, approvals and publishes. It also records secrets saved or deleted (never their values), and API keys and access tokens created or revoked.
Sub-processors
- Cloudflare: hosting, running scripts, object storage, networking, bot protection, web analytics
- Neon: managed PostgreSQL database
- Resend: transactional email
- Stripe: payments and invoicing
Compliance
We haven't completed a third-party audit (such as SOC 2) yet. We can sign a data processing agreement on request. Ask us about our plans.
Reporting a vulnerability
Please report security issues privately to security@reminix.com, also listed at /.well-known/security.txt. Include what you found, where, and how to reproduce it. We reply within two business days, and ask for reasonable time to fix an issue before anyone makes it public.