Alloyqa
Trust

Security at
Alloyqa

AlloyqaEffective September 5, 20266 sections

Alloyqa works with your code, repositories, Tasks, and coding agents. We design execution to keep credentials, workspace data, and task environments separated and scoped to the work being performed.

01

Task and workspace data

Alloyqa stores the information needed to operate your workspace, including Tasks, statuses, Goals, reviews, feedback and activity, linked repository and pull-request metadata, execution attempts and results, and workspace membership.

Workspace access is checked against current membership. When a member is removed, they lose access on their next request.

02

Credentials

When you use This computer, Codex and Claude Code authenticate through their own local tools on your Mac. Alloyqa does not upload those local sign-in sessions to Alloyqa Cloud.

Cloud execution uses Alloyqa-managed worker and model-provider credentials, separate from the local subscriptions connected on your Mac.

03

This computer

Local Tasks run in isolated task workspaces. Alloyqa limits credential exposure during Git operations and checks for sensitive files before committing or pushing changes.

04

Alloyqa Cloud

Cloud Tasks run in isolated per-task execution environments with restricted access to unrelated workspaces, worker credentials, and host services.

If the isolated environment cannot be prepared safely, the task does not fall back to unrestricted execution.

05

GitHub access

GitHub access is scoped to the repository involved in the Task and uses GitHub App installation credentials.

06

Logs and secret handling

Alloyqa applies secret redaction to execution and preview logs before they are retained or transmitted. No automated redaction system can detect every possible secret format.

Last updated: September 5, 2026