Encryption in transit
All API, dashboard and webhook traffic is served over HTTPS.
Trust Center
OneShot has completed its SOC 2 Type II audit. OneShot is GDPR compliant. Your agents send real data through OneShot: messages, contacts, payments. Here is how we protect it, who processes it, and how to verify what happened yourself.

01
How data is protected in transit, at rest and in our own systems.
All API, dashboard and webhook traffic is served over HTTPS.
Databases and file storage are encrypted at rest by Google Cloud. Sensitive fields, such as agent profile data and access tokens, are also encrypted with Cloud KMS keys.
Provider credentials and signing keys live in Google Secret Manager and are injected at runtime, never stored in code.
OneShot has completed its SOC 2 Type II audit. Request the report through our compliance portal.
OneShot is GDPR compliant.

02
How API access is issued and protected.
API keys are stored only as hashes. We cannot read a key after it is issued.
Repeated failed authentication attempts trigger escalating lockouts.
The OneShot API and worker each run as their own service account, limited to the queues, keys, buckets and secrets they use.

03
Controls on what agents can spend and proof of what they did.
Daily and per-transaction limits are enforced before a paid action runs.
Every paid action returns an Ed25519-signed receipt you can verify offline with our public key.
Agent code runs in isolated, short-lived sandboxes, separate from OneShot infrastructure.
Verify it yourself
Every paid action returns a receipt signed with Ed25519. Verify it offline with our public key, using the SDK's verifyReceipt() or the oneshot-verify-receipt CLI. No call to us required.
Subprocessors
The providers OneShot sends customer data to, and what for. We update this list before a new provider goes live.
Product analytics for the API and dashboard.
Tracing of model calls for debugging and quality.
Hosting, databases, queues, storage and key management for the OneShot API and workers.
Hosting and domains for sites built by agents.
Agent mailboxes on branded domains (send and receive email).
Public web and social profile collection for research.
Web page retrieval for sites that block automated access.
Web page retrieval for research.
Web and local business search.
Models for agent reasoning and content safety.
Hosted browsers for web automation tasks.
Isolated sandboxes for agent code execution.
Alternate executor for long-running research tasks.
Models for content safety checks and voice.
Model routing for agent reasoning, research and drafting.
Transactional and agent email delivery, inbound email webhooks.
SMS sending and phone numbers.
Outbound and inbound voice calls.
Registration of customer sending domains.
Warmup of agent mailboxes to protect deliverability.
Printing and mailing physical letters.
DNS, CDN and DDoS protection; DNS for customer sending domains.