Security and Privacy

Your security, safety, and privacy is our top priority.
We build CodeWords accordingly.

The basics

  • CodeWords is a platform that takes you from prompt to production so you can build automations without a developer. It integrates with over 2,700 other tools.
  • You have full control over how CodeWords uses your integrations and secrets at all times, and you can connect or disconnect at any time.
  • CodeWords uses best-in-class providers to power your chat and building experience: ElevenLabs for voice transcription, and Anthropic for AI.
  • We're in the process of completing our SOC2 compliance certification with independent auditors so you won't just need to take our word for it. We'll announce this once it's been finalized.

You control who sees your workflows

  • You control who sees your workflows. Workflows are private by default, and only you can access them until you choose to share.
  • If you do choose to share your workflows, your integrations and secrets will not be shared unless you explicitly enable this.

Everything stored in industry standard, encrypted infrastructure

  • All data is encrypted at rest and in transit, hosted on AWS infrastructure with access scoped to authenticated users — no one else can see your conversations or workflows.
  • Voice data is processed in real-time for transcription and is not stored on our servers. Only the resulting text is retained as part of your workflow.
  • For OAuth integrations (Google, Slack, etc.), we use industry-standard token management through certified partners. We only store a secure reference — your actual access tokens never touch our database.
  • User-provided API keys and credentials are stored securely in our database with access restricted to your account. Secrets are only injected into your workflows at runtime and are never logged or exposed in responses.
  • CodeWords runs entirely on isolated, sandboxed infrastructure — each workflow execution runs in its own secure environment that is destroyed after completion.
  • CodeWords is built and maintained by our top-tier engineering team, who've built scalable infrastructure for companies like Microsoft, TikTok, and Starling.

You can access our Terms and Conditions and Privacy Policy for more information.

Still have a question?

How is my code and data isolated from other users?

Yes, completely. Every time your workflow runs, CodeWords creates a brand-new, private environment just for you. Your code and data are never mixed with anyone else's. Once your workflow finishes, that environment is wiped clean — nothing is left behind. If you choose to save data between runs (like tracking changes over time), that stored data is also kept separate and only accessible by your workflows.

How are my passwords and API keys kept safe?

Your credentials are encrypted and stored securely by CodeWords. They're never written into your workflow code, never shown in logs, and never saved to disk. They're only made available to your workflow at the exact moment it runs — and only for that run.

Who can access and run my workflows?

Only you can access your workflows, unless you choose otherwise. Every workflow request requires your personal API key to be verified before anything runs. CodeWords also limits the number of requests to protect against misuse. You control the visibility of each workflow — keep it private (just you), make it public (available to other CodeWords users), or share it as a template (others can copy and customize it, but your data and credentials stay yours).

Is any of my data stored after a workflow finishes?

Not by default. CodeWords uses a "clean room" approach — each run starts fresh and everything is wiped when it's done. There are no files, no leftover data, and nothing persists on the platform. If your workflow needs to remember something between runs (like checking whether a website has changed), you can opt-in to secure, encrypted storage that only your workflows can access. You decide what gets saved and for how long.

What happens when my workflow connects to other apps like Gmail or Slack?

CodeWords handles the security for you. When you connect to services like Gmail, Slack, Google Sheets, or any of the 2,700+ supported integrations, you authenticate once through a secure process. After that, CodeWords manages your connection tokens safely — they're never visible in your workflow code. All communication with external services is encrypted, and incoming events (like "new email received") are verified by the platform before reaching your workflow.

Your ideas
deserve better.