ProcedureDeterministic AgentsMarketplaceSecurityClaude Co-Work Alternative
Book a Demo
ProcedureDeterministic AgentsMarketplaceSecurityClaude Co-Work Alternative
Book a Demo
GDPRSOC 2NISTComing soonISO 27001Coming soon

Security

Built for work you cannot afford to get wrong

Isolated execution, credentials that stay in your vault, access scoped by role, and a record of every run.

Book a DemoView Trust Center

Isolated execution

Every run starts in an isolated environment

Stepwork keeps automated work separated from the browser sessions and applications your team uses every day.

A machine in your environment

Flows execute in an isolated browser container on a machine in your environment. Nothing runs directly against a user’s everyday browser session.

A container in the Stepwork cloud

Cloud containers provide an isolated environment for scheduled and unattended work without depending on a local machine being awake.

Credential protection

Your credentials and keys stay protected

Stepwork keeps credentials, identity connections, and API keys protected throughout every run. Secrets are retrieved only when needed, encrypted at rest, and never exposed to Stepwork employees.

How credentials and secrets are handled

  • Credentials are retrieved only when a flow runs
  • Passwords are never pasted into procedure variables
  • Existing sign-in methods and identity providers, including Okta, remain in place
  • API keys are encrypted and managed through AWS KMS, with no employee access
  • App credentials never leave your local environment
  • Okta
  • 1Password
  • API secrets

Security controls

Control who can act, what can run, and what gets recorded

Connect Stepwork to your existing identity systems, define access by role, require approval for sensitive steps, and maintain a complete record of every run.

A complete record of every run

Each run records the steps taken, the outcome, any failure reason, who triggered it, and whether it ran manually or on a schedule. If a step fails, the record shows exactly where the process stopped and why.

Role-based access

Administrators, managers, and members can configure, manage, and run different parts of Stepwork based on their responsibilities.

Organization isolation

Data, flows, Procedures, and run records remain scoped to the customer’s organization.

Secure API key storage

API keys are encrypted at rest with AWS Key Management Service. Keys are decrypted only when a flow needs them.

Use your existing identity system

Single sign-on connects Stepwork to the identity provider your organization already uses.

Require approval for sensitive steps

Selected steps can pause for review by a named approver. The run continues after approval, and the decision is recorded in the run history.

Share diagnostic data only when needed

You have full control over sending flow logs to the Stepwork team for support. You can turn sending off at any time and keep everything on your local device.

Privacy and compliance

Security documentation, ready when your team needs it

Review Stepwork’s current security practices, compliance information, and available documentation through the Trust Center.

View Trust CenterContact the security team
Stepwork

Deterministic agents for work that must run the same way every time.

ProcedureDeterministic AgentsMarketplaceSecurityClaude Co-Work Alternative
Terms and ConditionsPrivacy PolicyData Processing AgreementSubprocessors

2261 Market Street #4481, San Francisco, CA 94114, USA

Loot Discount inc dba Stepwork

© 2026 Stepwork. All rights reserved.