Security and audit
How The Anything AI protects your account, your apps and the people who use them.
Every app you build
- Roles: each app has a "Viewing as" switch, and actions a role may not take are locked with an explanation.
- Activity log: every create, edit, delete and status change is logged with time and role, and can be exported as CSV.
- Sealed hosting: hosted apps run in a sandbox with a strict content security policy. They can't load outside scripts, make network requests, or read your account's cookies.
- Privacy kit (Builder and up): consent banner, privacy notice template, data retention setting and masking of personal details.
- Certainty labels (Builder and up): computed figures show what they're based on and how reliable they are.
Your account
- Passwords are stored with a one-way hash; sign-in is rate-limited against guessing.
- Every sign-in, build, export, payment and setting change is recorded in your account audit log, exportable as CSV. Retention: Free 7 days; Builder 30 days; Business 365 days; Enterprise 730 days;
- Private apps (Builder and up) can only be opened by you while signed in.
- Enterprise organizations can require single sign-on through their own identity provider (OpenID Connect), and can request a data processing agreement.
Payments
Payments run on PayMongo's hosted checkout. We never see or store card or e-wallet details, and every payment is confirmed directly with PayMongo before a plan or credits are applied.
AI processing
Descriptions and app code are sent to our AI provider to build and test apps. See the Privacy Policy.
Report a problem
Found a security issue? Email hello@theanything.ai. We'll respond within 5 business days.