Home/Security and data handling

How Qoren secures managed agent environments

Agents hold credentials and take actions, so the platform that runs them has to be specific about security. This page describes how Qoren isolates environments, protects secrets, limits what a single agent can do, and handles your data, including the third-party services involved.

Start free trialRead docs

By David SilvaPublished

Direct answer

How does Qoren secure hosted agents?

Each environment is a dedicated, isolated cloud machine, and each agent on it runs as its own system user with hard memory and CPU limits. Stored secrets are encrypted at rest with AES-256-GCM and revealed only where the agent needs them. Model spend stops at a hard cap you set. Magentic Studio, the Portugal-based operator, acts as GDPR controller for account data and as your processor for data your agents handle, with a DPA available on request.

Subprocessors and third-party services

The services Qoren uses to operate the platform, and what each one touches.

ServiceRoleData involved
DigitalOceanHosts agent environment machines.Agent workspaces, files, and runtime state.
OpenRouterModel access for managed keys and BYOK.The inputs and outputs your agents send to models.
ConvexApplication backend and database.Account, configuration, and operational data.
PolarPayment processing.Billing details; full card numbers never reach Qoren.
PostHog (EU)Product analytics.Usage events and device data.
ResendTransactional email.Email addresses and message content we send you.
AgentMailPer-agent email inboxes (optional add-on).Mail sent and received by agent inboxes you enable.

Isolation: one environment, one machine

Every Qoren environment is a dedicated virtual machine provisioned for you on DigitalOcean, not a shared container pool. One client's or project's agents, files, logs, and the keys written to them live on their own machine, separated from every other environment you run and from every other customer. Within a machine, each agent runs under its own system user with enforced memory and CPU ceilings, so a runaway agent is contained twice: by its user boundary and by its resource limits.

  • Dedicated virtual machine per environment.
  • Dedicated system user per agent, with memory and CPU limits enforced by the service manager.
  • No shared agents or workspaces across environments; vault keys saved to one client reach only that client's agents.

Secrets: encrypted at rest, revealed deliberately

Credentials you store in the vault are encrypted at rest with AES-256-GCM. Listings are write-only by default: the dashboard shows that a secret exists, not its value, and revealing a value is an explicit, audited action. Secrets reach an agent only when you give them to it or a template you deploy asks for them by name, and the deploy form lists every key it fills in from the vault. An agency can save a key to one client so that only that client's agents can receive it. SSH keys used to manage machines are stored encrypted and decrypted only into ephemeral files during use. Traffic between your browser, the platform, and agent machines is encrypted in transit.

  • AES-256-GCM encryption at rest for stored secrets and SSH keys.
  • Write-only listings; value reveals are explicit and audited.
  • Per-agent injection, with every vault key listed on the deploy form, not blanket sharing.
  • TLS in transit throughout.

Blast radius: what one compromised agent can reach

The platform assumes any single agent could misbehave and keeps the damage bounded. An agent sees only the credentials you gave it, on the machine of its own environment, under its own system user. Model spend draws from your credit balance and stops at the cap, so a looping agent cannot generate an open-ended bill. Health monitoring raises alerts when an agent's process fails, goes offline, or degrades, and current service status is public.

  • Least-privilege by structure: per-agent user, per-environment machine, opt-in secrets.
  • Hard spend caps; you are never billed for usage you did not pre-pay.
  • Health alerts on failures, offline machines, and degraded agents.

Sources: Qoren service status

Account access

Sign-in supports GitHub and Google OAuth, email one-time codes, and passwords. Billing is handled by Polar; Qoren does not store full card numbers.

Your data: controller, processor, and the DPA

Magentic Studio is the data controller for your account data. For personal data your agents process on behalf of your business or your clients, you are the controller and Qoren acts as your processor, following your instructions and configuration. A data processing agreement is available on request. Data may be processed outside the EEA through subprocessors, protected by the European Commission's Standard Contractual Clauses. When you delete your account, associated data is removed in a cascade rather than orphaned.

  • GDPR controller/processor split, stated plainly in the privacy policy.
  • DPA available on request at hello@qoren.sh.
  • EU-based operator; SCCs for transfers outside the EEA.

Reporting a vulnerability

If you believe you have found a security issue in Qoren, email hello@qoren.sh with the details and enough information to reproduce it. You will get a human response, and we ask for reasonable time to fix confirmed issues before public disclosure.

Frequently asked questions

Is my data isolated from other customers?

Yes, structurally. Each environment is a dedicated virtual machine, and agents within it run as separate system users. Nothing about the isolation depends on application-level filtering alone.

How are secrets stored?

Encrypted at rest with AES-256-GCM. The dashboard lists secrets write-only, revealing a value is an explicit audited action, and secrets are injected only into the agents you choose.

Do you offer a DPA?

Yes, on request at hello@qoren.sh. The privacy policy already documents the controller/processor split: Magentic Studio is controller for account data and processor for data your agents handle.

Where does my data live?

The operator is based in Portugal, and data may be processed by the subprocessors listed on this page, some outside the EEA under Standard Contractual Clauses. Product analytics run on PostHog's EU cloud.

Can a runaway agent create an unbounded bill?

No. Model spend draws from your monthly credit grant first, then from any topped-up credits, and stops at the hard cap. You are never billed for usage you did not pre-pay.

What uptime evidence do you publish?

Service status and history are public at status.magentic.studio, and environments are health-monitored with alerts inside the product.

Run OpenClaw, Hermes or Codex agents 24/7, without the homework.

Qoren runs the machine, the secrets, the updates and the logs, with a hard cap on credit spend. Start from a template and have an agent working today.