How BIOS is built to be trusted.
BIOS gives software agents the keys to a real business. That only works if the keys are never actually in the agents' hands, if one customer can never see another, and if nothing irreversible happens without a person. Those three ideas shape the whole system.
Credentials are brokered, never held
Platform tokens and AI-subscription tokens are encrypted at rest with a master key that lives only on the server. No credential is ever placed in an agent's prompt, tool result, message, memory, or run log. When an agent needs to call Shopify or Klaviyo, a broker makes the call on its behalf and returns only the data. The server's own test suite forbids any paid-API SDK from entering the codebase, so agents run on the subscriptions you sign in with, not on keys we hold.
Every customer is isolated
Each customer is a tenant. Every tenant table in the database has row-level security forced on, including for the database owner, so a query without the right tenant context returns nothing. Prompts run neutralized so no tenant context can leak across a run. A two-tenant isolation test runs with the rest of the suite on every change.
Agents earn autonomy, they are not given it
- T1 actions are reversible in seconds and invisible to customers. Fifteen clean approvals and an agent may run them on its own.
- T2 actions are customer-facing and irreversible. Thirty clean approvals plus a per-action cap.
- T3 actions (price changes, full-list sends, refunds, deletes, permissions, spend above cap) are never autonomous. Always a tap.
Tier checks live in the runtime, not in the agent's instructions, so an agent cannot talk its way past one. Promotion widens the envelope but never removes the hard rails, and a single boundary violation demotes the agent back to training.
Minimum scopes
Connectors request only the scopes a shipped capability actually uses: read-only for Shopify, Meta, Google Ads, and calendars; Klaviyo campaign writes only because approved agents draft campaigns. Scopes grow only when a new capability needs them.
In transit and on device
All traffic between the apps, the server, and the platforms uses TLS. Sessions are bearer tokens scoped to a user and device and can be revoked from the app.
Report a vulnerability
If you find a security problem in BIOS, email sutton@helionhq.com. We read every report and will reply within 3 business days. Please give us a reasonable window to fix an issue before publishing it.