Safe by design
Built for work that touches real customer data
Documenting how your business runs means recording the systems it runs on. Password fields are never recorded, and your documentation stays in your workspace. These are the things we decided could not be left to a settings page.
The short answer
Four things that are true on every plan
- Password fields are never recorded
- Password boxes and anything marked secure are skipped while the recording happens. Emails and card numbers are stripped from typed text before it is stored.
- Nothing is published until a person approves it
- Every SOP arrives as a draft. Its owner, a manager of its team or an admin publishes it, and there is no setting to skip that.
- You choose who can read each SOP
- Keep it private, share it with its team, or make a link anyone can open without signing in. A person decides, one SOP at a time.
- Your AI reads with a key you control
- Each person connects their own AI with a personal key that expires on a date they choose. It sees what they can see, and it is read-only unless they allow edits.
The basics are covered too. Each workspace is sealed off inside the database, credentials are encrypted and never sent to an AI model, and nothing you record is used to train one.

In more detail
What cannot happen, and why
Each of these is built in. None of them is a checkbox somebody has to find and tick.
- Password fields are never captured in the first place
- Password and secure fields are skipped as the recording happens, screenshot and typing included. Emails and card numbers are stripped from the recorded text before it is stored. From Pro up you can add your own patterns for what else to strip.
- Nothing happens because software decided it should
- Every SOP is created as a draft and reaches your team when a person approves it. Skills and agents work the same way: no agent runs until somebody deploys it, and any action it takes can be set to stop and ask first.
- Your workspace cannot be reached from another one
- The separation is enforced by the database itself, not by our code remembering to check on every screen. A mistake in a query cannot return another customer's work, because the query is never given the chance.
- Credentials are encrypted, and never sent to an AI model
- Keys for your connected systems are encrypted the moment you save them. Steptree applies them on its own servers when a call is made. No AI model ever sees one, and none can be read back out of a transcript.
- A limit caps what an agent's mistake can cost
- Every agent carries a limit on how many steps it may take, what one run may cost, and how many times a day it may run. You set all three, and they are enforced where the money is spent.
- Steptree AI's chat can use a model on your own hardware
- On Team and above, Steptree AI in the Steptree App can use a model on your own network instead of a hosted one. Recordings are still uploaded to your workspace, and SOPs are still written by a hosted model.
The riskiest thing Steptree AI does, it asks about first
Letting Steptree AI or an agent use your keyboard and screen is the riskiest thing either can do, so it gets the most safeguards. Every action is described before it happens. A click aimed at a screen that has moved is refused. Stop means stop. Here is what that looks like in practice on where agents run.
For larger organisations
What Enterprise adds
Everything above applies to every plan. These are what a security team asks for on top.
- Single sign-on and automatic provisioning
- SAML 2.0 or OIDC with your identity provider, plus SCIM. Somebody leaving your company loses access here without anybody having to remember.
- Audit logs you can export
- A record of who did what, in a form your SIEM can read, rather than a screen somebody has to screenshot.
- Your own instance
- A dedicated single-tenant deployment rather than a share of a common one. There is no choice of data region and no customer-managed encryption key today.
- Your questionnaire, answered by a person
- Send it. We would rather fill it in than have your security team guess from a marketing page. You will be talking to somebody who can answer the technical questions, not a queue.
Questions
Asked in every review
- What happens to sensitive information in a recording?
- Password and secure fields are skipped as the recording happens, so they are never captured. Emails and card numbers are stripped from the recorded text before it is stored. Each workspace is sealed off inside the database rather than by application code remembering to check. Screenshots are kept as taken, and any step can be deleted before the SOP is written.
- Who inside our business can see a procedure?
- SOPs belong to teams, and access follows team membership. So the finance close is visible to finance, not to everybody with a login, unless somebody makes a public link for it. Admins can see the workspace's usage and activity.
- Does our data train anybody's model?
- No. Your recordings and SOPs are used to write your documentation, answer your questions and run your agents, and for nothing else.
- Can we delete it?
- Yes — recordings, procedures and the whole workspace. What we hold, for how long, and how to ask for it back or ask for it gone is set out in the privacy policy.
- Where is it hosted?
- On managed infrastructure in the cloud, with payment details handled by Stripe and never reaching our servers. Enterprise customers can have a dedicated instance, but there is no choice of data region today. Send us your questionnaire and we will answer it properly.
- How do we report something that looks wrong?
- Raise it from the Support menu once you are signed in, or email support@steptree.ai. Tell us what you found and how to reproduce it; please don't test against another customer's workspace.
Next
Where to go from here
Privacy policy
What we collect, why, how long we keep it, and your rights over it.
What an agent may do
Approvals, limits, and the refusal to deploy something that could never have worked.
Send us your questionnaire
A reply within one business day, from somebody who can answer the technical questions.
Do one real job once, and read the SOP Steptree writes
Record it on Windows or Mac. Steptree writes the SOP with the goal, the steps and the judgement calls. Approve it, share it with your team, and connect your AI. Free to start, no card.
