Encryption
In transit. Every connection to spacesheep.dev, spacesheep.app and mcp.spacesheep.dev is HTTPS. Both .dev and .app are HTTPS-only domains, preloaded into every major browser, so plain HTTP is never served.
At rest. Your spaces, their version history, your account data, messages and saved secrets are encrypted at rest with AES-256.
Passwords are never stored. We keep a salted PBKDF2-HMAC-SHA-256 hash with a high iteration count, stored per account so it can be raised over time.
API keys and OAuth tokens are stored as SHA-256 hashes. A key is shown to you once, when it is created; we cannot show it again.
Sessions-only keys. A key made as Sessions only in Settings → API keys can report coding sessions from a machine's hooks and nothing else: no MCP, no publishing, no reading your spaces or memory. It is the kind to leave in a hook config, so a copied config file exposes nothing.
Infrastructure
spacesheep runs on a global edge network with no servers of our own to patch or leave open, and every request passes through DDoS protection.
Isolation between spaces
Separate origin. Published pages are served from their own subdomain on a separate domain (<id>.spacesheep.app), inside a sandboxed frame. A page's script cannot reach your spacesheep.dev session or the dashboard.
Per-space sessions. The session a page receives is signed with a key unique to that space, and every content server refuses it on any other space.
Security headers. Every page carries a Content Security Policy and standard hardening headers; new accounts' pages are further restricted to their own origin.
Access control
Private by default. Each space has an access level you set (private, shared with named people, your team, or open), and one access check guards every way in: the viewer, the content server, the API and the MCP server.
Sign-in is Google or an email and password. Session cookies are HttpOnly, Secure and SameSite.
Connected apps (Claude, ChatGPT, Grok and other clients) use OAuth 2.1 with mandatory PKCE and exact redirect-URI matching. Each connection is listed in Settings and can be revoked there instantly.
Least privilege for agents. An agent acting for someone other than the space's owner runs contained: no access to the owner's memory, private integrations or settings.
Your secrets
Keys you save for your agent or your spaces are write-only: the API never returns a secret's value.
When coding-session activity is sent to spacesheep, credentials are redacted twice, once on your machine before anything is sent and again when it arrives, so passwords, tokens and connection strings never reach your stored history.
AI and your data
The agent runs on the model provider you choose, under that provider's terms. Nothing is sent to a model unless you use the agent.
We never use your spaces or conversations to train models, and we don't sell personal data.
Abuse prevention
Every API action is rate-limited per account and per IP. Sign-in has its own per-IP and per-account limits, and signup and password reset are protected by a bot challenge.
Content is screened at publish time, and new accounts' pages are served with tighter restrictions for their first week or two.
Reports of phishing or other abuse go to a human and are typically acted on within one business day: report abuse.
Your data, your control
Every space keeps its full version history, and you can restore an earlier version or delete a space at any time.
Pro accounts can back up every space to their own Google Drive daily.
To delete your account and everything attached to it, email support@spacesheep.dev. See the privacy policy for what we store and which providers process it.
Reporting a vulnerability
If you find a security issue, write to support@spacesheep.dev (also published in our security.txt). Please give us a reasonable window to fix it before publishing details. We read every report and will keep you updated.