Security
This page describes how AIowa Agents handles access, credentials, and operational security for client AI workflows. It is an operational trust document, not a marketing claim. We do not make certification or regulatory compliance claims on this page.
How we approach security
Minimum-necessary access
We scope agent permissions to exactly what the workflow requires — nothing more. An inbox triage agent doesn't get calendar write access. A document router doesn't get send rights. Permissions are defined before any build begins.
Human approval during initial rollout
Every new workflow starts in draft or review mode. The agent proposes actions; you approve them. Nothing is sent, filed, or executed autonomously until you've reviewed real outputs and explicitly authorized the next level of autonomy.
Scoped permissions
We do not request broad account access. Scopes are narrowed to the specific actions the workflow needs and documented before integration. If a required permission seems broader than expected, we'll flag it and discuss it with you.
Credential ownership stays with you
Accounts, API connections, and workflow credentials are set up in your name wherever practical. You are the owner. We operate on your behalf — we don't hold credentials you can't independently rotate or revoke.
Ability to revoke access at any time
You can revoke agent access at any time without waiting for us. We will walk you through the revocation process for each connected tool as part of the workflow handoff. No lock-in.
Visibility into agent actions
You can see what your agents are doing. Every draft, every sort, every routed document is logged. We don't run black-box automation — the outputs are reviewable.
Separation of inquiry and provisioning
The public intake form at /start is for business inquiries only. Credential provisioning — connecting your tools to agent workflows — is a separate, supervised process that happens after an engagement is established. We will never ask for passwords or API keys through a public form.
Secure handoff process
When an engagement requires credentials, we use a defined handoff process with clear documentation. This process is explained and agreed before any integration begins. We do not accept credentials through uncontrolled channels.
Client-owned accounts
Wherever practical, integrations are configured under accounts you own. We operate as a service provider with delegated access — not as a gatekeeper who controls your infrastructure. When an engagement ends, you retain full ownership and control.
Security contact
If you have a security concern, question about an active engagement, or need to report a potential issue, contact us directly:
We respond to security inquiries personally. Please do not send credentials, keys, or sensitive account details in your initial message.
For information on how we handle data submitted through our intake form, see our Privacy Policy.