Know where your data goes
Understand workspace permissions, onsite execution, and the information shared with your selected AI provider.
The onsite boundary
Equipment credentials and raw terminal or API sessions remain on the Engine. The cloud coordinates approved work and receives bounded, normalized results. The agent does not get a raw device session or an equipment credential.
Workspace and client permissions
Access depends on your signed-in account, current workspace membership, role, stored OAuth grant, and tool policy. A grant selects one workspace and never expands your application role.
Tools are pinned to exact reviewed connector and contract digests. Unknown or unauthorized operations are absent from discovery.
Your selected AI provider
When an external agent invokes a tool, its provider receives the submitted arguments and normalized results. Infrastructure or customer context in those inputs and results is shared with that provider.
The provider controls its own chat history, retention, training, and enterprise settings. ConvergeSense does not store the external agent conversation. Review the consent notice and select a provider account suitable for the data you intend to use.
Result access and revocation
Normalized job results are available for 15 minutes after completion. Result access remains tied to the originating user, client, workspace, and grant.
Owners can disable or revoke integrations from Agent connections. Revocation blocks catalog and result access on the next request. Removing a workspace member also revokes their agent grants and sessions.
Reporting a concern
Send security reports to security@convergesense.com. Include safe request or job identifiers, the impact, and reproduction steps. Do not submit credentials, raw device output, or customer records in a public GitHub issue.
See the current security overview, privacy policy, and subprocessors for more information.