Where is my data stored?
In Amnetic's own AWS account, in the US (Oregon). Files go in a private storage bucket under random object keys; your file names live in our database, not in the bucket.
In Amnetic's own AWS account, in the US (Oregon). Files go in a private storage bucket under random object keys; your file names live in our database, not in the bucket.
At rest, yes: AES-256 server-side encryption on the bucket and encrypted database storage, both with AWS-managed keys. In transit, your browser and API clients connect over TLS 1.2 or newer.
There is no per-customer key. You are trusting Amnetic and AWS, not a key you hold. If you need to bring your own key, contact us.
Basic room details: its name and purpose, size, current version and how many members it has. Not your file list, not your file names, not who the other members are. There is no download path for members; the only thing they can do with your data is ask an agent to analyze it.
Each run is pinned to a fixed version of the room's files plus the supporting files the requester chose. Later uploads or removals don't change a run already admitted.
The run executes in a fresh, single-use virtual machine. Its network is locked down at the VM boundary by the sandbox provider, not by software inside it: all outbound traffic is blocked except to a fixed allowlist of Amnetic's own services and storage, plus a public DNS resolver. Inside the VM, the agent process is also cut off from the network entirely; its model and marketplace calls are relayed for it over a local connection. The agent can only read the run's inputs, work inside the sandbox, and submit a report. Nothing carries over between runs.
The sandbox runs on E2B, a third-party sandbox provider. Your files are loaded into it for the duration of the run.
Only a text report you have read and released, plus a signed receipt describing the run (hashes, sizes, timing and cost). Reports are capped at 64 KB, fenced code at 16 KB, and long encoded blobs are rejected. No files are ever delivered to a member.
A report can quote your data. Your review before release is the control, not an automatic filter.
No. Agents use Anthropic's Claude models running inside Amazon Bedrock, in AWS's US regions, not on Anthropic's servers. Bedrock does not share your data with Anthropic or any other model company, and does not use it to train models. Amnetic doesn't train models on your data either.
The agent's sandbox has no route to any model company: apart from DNS, it can only connect to Amnetic's own services and storage. Cleanroom model calls go through our gateway, which forwards only to Bedrock and never logs prompts or responses. Details are in our privacy policy.
Technically, yes. Your data is encrypted with AWS-managed keys, so an Amnetic administrator with production access can read it. There is no feature that shows staff your files.
Direct access to production databases runs through a break-glass session that is recorded and kept for a year. Every read of the storage bucket, by anyone, is logged by AWS CloudTrail and kept for a year.
Members lose access immediately; a run still in progress is stopped by the wipe that follows. A background job then deletes every stored version of your files from the bucket, scrubs the room's title, requests and reports from the database, and replaces file names with hashes. Completion is recorded with a signed event.
Runs you already released, request and report, stay with the members who received them. Database backups expire after 35 days and application logs after 90. Removing a single file takes it out of future runs; its bytes are deleted when the room is.
Closing your account wipes every room you own. See what account closure removes.
Who joined or left, who was granted or lost access, each request and the decision on it, which files an agent read, and each wipe. These records name files; they never contain file contents, prompts or reports. Website analytics are first-party and cookieless, described in our privacy policy.
Email harrison@amnetic.ai. You will hear back from the founder.
Machine-readable version for agents: security.json