sidekin

Sidekin / Security

Security at Sidekin

Reviewed October 6, 2026

Useful assistance depends on access you can understand. Here is how Sidekin protects accounts and information, and where other services are involved.

Account access

Sidekin separates registration from admission. Signing in does not automatically grant access to the private assistant or connect an outside account. Google sign-in uses WorkOS. Phone access uses a verified messaging relationship and short-lived, single-use sign-in links. Sessions can be revoked.

Your assistant, saved records, and enabled connections are associated with your account. Access checks and database ownership policies restrict requests to the appropriate owner. Administrative access has separate authentication requirements.

Stored information

Sidekin encrypts sensitive application records, including connection credentials, phone profiles, conversation records, and prepared replies. Its application encryption uses AES-256-GCM with record context so encrypted values cannot simply be moved between unrelated records. Recovery backups also contain encrypted account data.

Our website and application use HTTPS. Messaging, telephone, connected-service, and hosting providers have their own processing boundaries. Sidekin’s servers must process information to provide the assistant, so these controls do not mean that all information is end-to-end encrypted or inaccessible to the operator.

Connections and actions

You choose which supported accounts and tools to enable. Connecting a service supplies access within its approved permissions; it does not itself instruct Sidekin to send a message, buy something, or delete information. External connector credentials stay in encrypted application state rather than being placed in the assistant’s workspace.

Tool execution checks current account permissions. Source-event changes through calendar management tools require the relevant provider permission and a prepared change. Creating a personal event or a booking uses a separate submission flow. Disconnecting a service stops future use through that connection, but it does not reverse work already completed. You may also need to revoke authorization with the provider.

Sidekin records action status and uses safeguards against repeating uncertain external writes. A request, prepared reply, or delivery receipt is not proof that a third party completed the requested outcome. Review important results and report discrepancies.

Assistant and computer access

Assistant inference follows the provider selected for the feature. The Tinfoil option verifies its inference endpoint and encrypts that exchange. It does not extend that protection to every part of the application: conversation storage, tools, messaging, telephone services, and execution providers have separate responsibilities.

Enabled computer features use account-scoped workspaces and browser access. Provider credentials and execution authority are controlled outside ordinary task files. Those workspaces can retain files and browser state between sessions; see the Privacy Policy for the relevant data handling.

Protecting your account

Contact about security

Send suspected vulnerabilities or account-security concerns to deep@onepatch.dev. Include enough information to understand the issue, but omit credentials and other people’s private data. Please avoid accessing other accounts or disrupting the service when reporting a problem.

This page describes implemented controls, not a certification or a guarantee against every threat. Features and safeguards can change as Sidekin develops. Data retention and deletion details are in our Privacy Policy.