security

An agent in your production data, on a short lead.

A coding agent connected to Vinktar reads what you let it, writes only inside your workspace, and leaves a record of every call. Here is how each of those holds, where your data lives, and what we do not have yet.

the_grant

One workspace, one choice of access, approved by a person.

  • An agent connects with OAuth 2.1 and PKCE, so there is no API key to paste into it: a person signs in, in their own browser, and approves one workspace, optionally one project, read only or read and write. The token it gets is good for that grant only.
  • Two checks run on every call. The connection’s grant is checked against every id the agent passes, and the person’s own membership is checked by the same resolvers the web app uses, so an agent never sees more than the person who approved it.
  • Read and write is offered only where that person can change data themselves. Any connection can be disconnected at any time; an admin can disconnect anyone’s, or switch agents off for the whole workspace, which refuses the next call.

vinktar · you approve the grant

vinktar.com/oauth/consent
✻⇄[ ]

Claude Code wants to connect

It will act as you, inside what you choose here.

Workspace

Acme

Project

web

Access

Read onlyRead and write
DenyAllow

can_and_cannot

Writes stay inside your workspace.

An agent can configure what it needs to answer questions and follow up. It cannot remove anything, create credentials, or name a new place for your data to go: there is no tool for any of those, and the one tool that could reach outward refuses to.

It can

  • Read events, errors, boards and trends in the scope you chose
  • Define events and write the project’s notes
  • Build, edit and delete boards and panels; a deleted one can be restored for 30 days
  • Create watches that reach your owners and admins
  • Resolve, ignore, reopen or assign an issue

writes need a read-and-write grant · mcp:write

It cannot

  • Delete events, errors, issues or projects
  • Create projects or API keys
  • Add a webhook, Slack channel or email list
  • Hide or un-hide an event or property
  • Touch members or billing
  • Run code or deploy anything

no tool for these · create_watch refuses a destination

The line is create_watch. An agent can create a watch, and it reaches the workspace’s existing owners and admins. A request that names a webhook, a Slack URL or an email list is refused with a sentence the agent can relay to you. Anything an agent changes on an issue is recorded as done by that agent.

hostile_text

What your users write is data, never instructions.

Error messages, event names, payloads and URLs arrive from anyone who can load your app, since the key that sends them is public by design. Some of that text will one day be written to steer an AI agent.

Marked as untrusted

Captured text is handed to the agent inside a <vinktar-data> block, cleaned of anything that could close it early, with the server’s instructions saying what that block is.

Links from ids only

Every link Vinktar gives an agent is built from ids we issued, never from a URL that arrived in your data.

Nowhere to send it

No tool sends data out or adds a destination. The only things an agent can delete are boards and panels, and a person can restore each for 30 days; no tool removes events, errors or projects.

the honest caveat

That lowers the risk; it does not remove it. An agent can still be misled about what it reads, and it has other tools than ours. Check what an agent proposes before you act on it, and be most careful with connections that can make changes.

vinktar · you correct it

vinktar.com/acme/projects/web/agents

acme / web

What agents made

  • Pricing page launch

    board · expires in 14d

    Claude Code Delete
  • Checkout errors spiking

    watch · to owners and admins

    Claude Code Delete

user.email

hidden from agents

staying_in_charge

You see what it did, and you can undo it.

Every call on the record

Each tool call is logged with its arguments, how long it took and what it cost, and shown on the project’s AI agents page for 30 days.

Everything it made, labelled

Boards, watches and event definitions carry the agent that made them. What agents know lists the boards and watches with a delete for each; a person’s edit to a definition wins.

Hidden properties stay hidden

Mark a property hidden from agents and it is refused in every query, filter and breakdown, and stripped from every result. Only a person can clear the flag, never a request over MCP.

Budgets and deadlines

Calls are budgeted per connection, per person and per workspace, at half the workspace’s read budget, and every warehouse read has a deadline. A monthly allowance stops a loop; it is never billed.

your_data

Where it lives, and how it is kept apart.

In Helsinki

The application, the event warehouse and the database run on UpCloud in Helsinki, Finland. Every third party that touches your data is on the subprocessor list, added before it first does.

No model provider

We run no model, so no AI company is our subprocessor. What your agent reads does go to your agent’s model provider, under your agreement with them: choose the scope with that in mind.

Tenancy in three layers

Membership is checked in the API, every query carries a tenant condition that cannot be removed, and every warehouse read is bound to your workspace and project ids.

SQL that can only read

SQL typed in Explore or sent by run_sql goes through our own compiler: SELECT only, your events only, allowlisted functions, every literal bound. It runs on a read-only connection with time, row and memory caps.

Two kinds of key

The write key in your app can only send events; it reads nothing. The source-map key is a secret, shown once when a person creates it, and never returned to an agent.

IPs are not kept

End users’ IP addresses are reduced to a keyed, non-reversible hash before storage. Deleting a project or a workspace purges its events and errors from the warehouse.

what_we_do_not_have

What we do not have yet.

If your review needs any of these, we are not the right vendor today, and it is better you know now.

  • No SOC 2 report

    and no other certification.

  • No region choice

    Your events and errors are stored in the EU, in Helsinki.

  • No SSO or SAML

    Sign in by email, password or Google.

  • A small company

    Deliberately so. Weigh it as the risk it is.

Found a vulnerability? Email john@vinktar.com.