Who can read your keys

Version: 2. Dated: 2026-09-23. Contact: legal@syncropic.com.

When you keep a key in a workspace we host (an API key you paste in, or an account you connect), this page says exactly who can reach it. It covers workspaces hosted by Syncropic. If you run a workspace yourself, you hold every credential that could read your keys, and nothing here applies to you.

Who in your workspace can use a key

A key you connect on a workspace's Integrations page is used only by the members you allow, which can be people as well as assistants. An assistant uses it only while it is working for someone who is allowed too. You can withdraw that at any time, and it stops at the next use.

A key you set on a workspace's Secrets tab is different today: any assistant in that workspace can use it. We are changing that, so that every key works the way connected ones do. Until then, if a key should be limited to the members you allow, connect it on the Integrations page rather than setting it on the Secrets tab.

Us

We run a hosted workspace with an administrator credential that we hold, so that we can start it, stop it, back it up and repair it. That credential can read a key you have stored.

We do not use it to read your keys, and none of our tools shows a key's value to anyone, including us. But we will not tell you it is impossible, because it is not.

What is recorded

Every time a stored key is looked up, your workspace writes down which key, who asked for it, and when.

There is one limit you should know about: the record shows that a key was looked up. It does not show whether the value itself was handed back. So treat every entry as though it was.

How your keys are stored

Your keys are kept on your workspace's own disk, where only the workspace can read them. They are not separately encrypted there. The machine protects them, which is how most hosted services protect their configuration.

Your daily backup keeps them encrypted. We hold the means to open that backup, because restoring it for you is our job. So the encryption protects your keys from anyone who gets hold of the backup file. It does not protect them from us.

If you need the answer to be "no one but you"

We can connect your workspace to a key vault that you run yourself. Your keys then never sit with us at all. Tell us at legal@syncropic.com and we will set it up with you.

Change log

VersionDateChange
12026-09-23First published.
22026-09-23Says "the members you allow" rather than "assistants", to match the Integrations page: a connected key can be allowed for people as well as assistants.