Security & trust

Autonomy you can actually trust

Giving AI employees real access to your tools only works if you keep control. TabHR is built so reasoning runs autonomously while authority to act sits behind isolation, approvals, logging, and a hard off switch you own.

A glowing container sealed inside a protective geometric vault of light

Isolation by design

Every virtual employee runs in its own dedicated Docker container, and tenants are isolated from one another. An employee's work, files, and credentials stay scoped to it.

Encrypted secrets

Integration credentials and API keys are stored encrypted. Employees receive only the access they need at runtime, never more than the role requires.

Least-privilege credentials

Connect each tool with scoped credentials so an employee can only touch the systems and permissions you grant. Revoke access at any time from the dashboard.

Human-in-the-loop approvals

Reading, research, and planning run freely; mutating or irreversible actions can route through your explicit approval first.

Full activity logs

Every employee writes to an activity log, so you can review what it did and why. You cannot secure what you cannot see, so everything is visible and auditable.

Instant off switch

Stop, redeploy, or terminate any employee instantly. Termination is a hard off switch that revokes its access immediately, from the dashboard or the API.

The safe-autonomy pattern

The safest way to run autonomous agents is to let reading, research, and planning run freely, while routing mutating, irreversible operations through explicit approval and policy checks, and to verify the real result after each action. TabHR keeps the model as a reasoning component while the authority to change things stays behind controls you own: scoped credentials, approvals, audit logs, and instant termination.

Learn more in our guide on AI agent security.

Have a security or compliance question?

We're happy to walk your team through our architecture, data handling, and access controls.

Contact us