Security

Your computer, still yours.

Rigby gives your laptop more power without giving anyone else your work. Here's how we keep it that way.

  • Your files and code are never used to train AI models.
  • Your work is isolated from every other customer's.
  • Everything is encrypted in transit and at rest.
  • Staff can't see your work without your permission, and every access is logged.

Your work stays yours

Your files, code, terminal sessions, and the work your agents do belong to you. Rigby stores them only so it can run your work, and never reads them for analytics, advertising, or training AI models.

Our operational logs record only what we need to keep the service healthy, such as connection status and how much power you're using. They never contain your credentials, terminal output, source code, screenshots, commands, or file paths.

Isolation

Your private cloud computer runs in its own isolated environment. Other customers can't see your work, and you can't see theirs.

When you close your account, we delete your private cloud computer and the data on it.

A private connection

Your laptop and your private cloud computer talk over a private, encrypted network built on WireGuard through Tailscale. Your cloud computer isn't exposed to the public internet, and only devices signed in to your account can reach it.

Previews of web apps your agents are building are forwarded to your laptop privately, so they're never published online by accident.

Access to your laptop

So your agents can work across both machines, your private cloud computer can reach your laptop while it's awake and connected. That's how agents use local files and screenshots, and run work that has to happen on your Mac, such as Xcode builds.

This connection uses the same private network, only links devices signed in to your account, and isn't available while your laptop is asleep or offline.

Signing in

Sign-in is handled by WorkOS. You sign in with Google or a one-time code sent to your email, so Rigby never stores a password for you.

Encryption

Data moving between your laptop, your private cloud computer, and our services is encrypted with modern TLS or WireGuard. Stored data, including your cloud computer's disk, is encrypted at rest with keys managed by our cloud provider.

Accounts and permissions

Your agents use an account such as GitHub only after you approve it. Tokens are stored encrypted, are never written to our logs, and you can disconnect an account at any time.

For companies, admins can invite people and remove their access. Your company's admin controls are kept completely separate from Rigby's own staff tools.

How our team accesses systems

Rigby staff don't open your private cloud computer or look at your work. If you ask for hands-on help, we'll request your permission first, and access is limited to that request and ends when it's done.

Staff access to our systems is granted on a least-privilege basis, enforced by our servers, and recorded in an audit log.

Payments

Payments are processed by Stripe. Your card details go directly to Stripe and never touch Rigby's servers.

Building it safely

Every change to Rigby is reviewed before it ships, and our code is scanned automatically for leaked secrets. Production systems are separate from development, and secrets never live in our code.

Compliance

We're building Rigby to meet the controls in SOC 2 and to support GDPR and CCPA obligations. Companies can request a data processing agreement and a copy of our security documentation by emailing us.

Reporting a vulnerability

If you believe you've found a security issue, please email security@tryrigby.ai with the details. We'll acknowledge your report within two business days and keep you updated as we fix it.

Please give us a reasonable chance to fix the problem before sharing it publicly, and don't access other people's data or disrupt the service while testing. We won't take legal action against research done in good faith.