Security

SwitchYard coordinates the work in the cloud and runs it on machines you control. This is what that means for your code, your accounts and your organization, including what it does not protect against.

Your code runs on your machines

The Local Agent runs on the machines you connect. It clones your repositories there, and runs there the agents and commands of each step. The agents themselves send what they work on to their provider (Anthropic, OpenAI, Cursor or GitHub), under your own account and that provider's terms.

The control plane, in the cloud, coordinates that work. It stores your workflow definitions, the state of each run, and the results and output your machines report back. It holds no copy of your repositories, but what an agent or a command reports, such as a summary or the end of its output, can quote your code.

Your agent accounts

Subscription tools such as Claude Code, Codex, Cursor and GitHub Copilot stay signed in on your machine, with your own account at each provider. The machine tells SwitchYard which of them it can run; their credentials never leave it.

The API keys your organization adds, for Anthropic or OpenAI, are stored encrypted in a key vault. Once saved, SwitchYard shows a key's name and never its value. A machine receives a key only while it runs an execution that needs it, and keeps it in memory for that execution alone, never on disk.

Machines

Each machine you add with “Add this machine” gets a key of its own. Deleting the machine in SwitchYard revokes that key, so it cannot connect again unless it is added anew.

A machine runs work only for its own organization. An Owner can tie an agent seat to one machine, and a machine can be set to run only one person's work on its Claude Code, Codex and Cursor subscriptions.

Organizations, roles and the audit log

Each organization's projects, workflows, runs and credentials are reachable only by its own members, its machines and the API keys it issues; only Owners manage its credentials. Each person in it is an Owner, who manages the organization, or a Member, who reaches only the projects they have been granted.

Changes made by people and by the organization's API keys are recorded in an audit log: who made it, which operation, when and with what result.

What is not isolated

Work running on the same machine is not isolated: one execution can read, and sometimes change, another's working copy, and can read the credentials another was given. A machine runs work from every project in its organization, so work that must stay apart belongs in separate organizations.

Where SwitchYard runs

The control plane, its database, its logs and the key vault run on Microsoft Azure, in the European Union (West Europe, in the Netherlands). Sign-in is provided by Clerk and our emails are sent by Postmark, both in the United States under the EU-U.S. Data Privacy Framework.

Questions

For any question about security, write to privacy@switchyardhq.io.

What personal data we process, why and for how long: our privacy policy