Safe, secure, and private.
Until is designed to keep your data safe and secure. For security questions or to report a vulnerability, email security@until.dev.
ComplianceUntil maintains SOC 2 Type II, ISO 27001, and GDPR compliance and periodically undergoes independent third-party security audits.
SOC 2 Type II
Until has undergone a Service Organization Controls audit (SOC 2 Type II).
ISO 27001
Until has undergone an Information Security Management System audit (ISO 27001).
GDPR
Until is GDPR compliant and has implemented organizational and technical measures aligned with EU data protection requirements.
AccessIsolated workspaces, role-based access control and identity management.
Workspaces
A workspace is the home for all plans, connections, and members. Data is never shared between workspaces.
Roles
Restrict access to Workspace settings and members. Roles are Admin and Standard.
Single sign-on (SSO)
Sign in with Google, GitHub, GitLab, Bitbucket, or Slack.
Approved Email Domains
Admins can verify a company email domain so teammates join without an invitation. New joiners are always assigned Standard permissions.
DataWe keep connections secure and encrypt secrets at rest.
MCP
Custom HTTP MCP servers use TLS and SSRF checks.
Webhooks
Inbound webhooks from GitHub, GitLab, Slack, and Linear are verified with HMAC.
Secrets
Until encrypts secrets at rest: OAuth tokens, webhook secrets, personal API keys, and push notification endpoints.
Audit Trail
Until records an append-only audit trail of what happened in a Workspace. When Until logs a tool call, it does not store the tool arguments or response body.