Safe, secure, and private.

Until is designed to keep your data safe and secure. For security questions or to report a vulnerability, email security@until.dev.

ComplianceUntil maintains SOC 2 Type II, ISO 27001, and GDPR compliance and periodically undergoes independent third-party security audits.

SOC 2 Type II

Until has undergone a Service Organization Controls audit (SOC 2 Type II).

ISO 27001

Until has undergone an Information Security Management System audit (ISO 27001).

GDPR

Until is GDPR compliant and has implemented organizational and technical measures aligned with EU data protection requirements.

AccessIsolated workspaces, role-based access control and identity management.

Workspaces

A workspace is the home for all plans, connections, and members. Data is never shared between workspaces.

Roles

Restrict access to Workspace settings and members. Roles are Admin and Standard.

Single sign-on (SSO)

Sign in with Google, GitHub, GitLab, Bitbucket, or Slack.

Approved Email Domains

Admins can verify a company email domain so teammates join without an invitation. New joiners are always assigned Standard permissions.

DataWe keep connections secure and encrypt secrets at rest.

MCP

Custom HTTP MCP servers use TLS and SSRF checks.

Webhooks

Inbound webhooks from GitHub, GitLab, Slack, and Linear are verified with HMAC.

Secrets

Until encrypts secrets at rest: OAuth tokens, webhook secrets, personal API keys, and push notification endpoints.

Audit Trail

Until records an append-only audit trail of what happened in a Workspace. When Until logs a tool call, it does not store the tool arguments or response body.