Skip to content

Security

You are handing us the keys. Here is what we do with them.

SmashSSO works by acting inside your tools as an admin account you log in with: your own, or one you create for it. That is a lot of trust, so this page says plainly what we hold, how it is protected, and where the limits are.

What we hold

Admin sessions
For each tool you connect by logging in, we store the cookies and browser storage that tool issued. This is what lets an agent act as the account you logged in with, and it is as powerful as that account.
API tokens
For tools connected by API, we store the token you gave us.
A Google refresh token
Read-only access to your Workspace user directory, so we can keep your list of people current.
Your access data
People, tools, roles, who has what, and a log of every run and change.

What we never hold

Your passwords
You type them into the tool's own login page inside the live browser. We do not record keystrokes or store what you type.
Your 2FA codes or seeds
Same. You complete 2FA yourself during the live login.
Your employees' credentials
Employees never sign in to SmashSSO and we never log in as them.

How it is protected

Encrypted at rest
Sessions and tokens are encrypted with AES-256-GCM before they reach the database. The key lives in the application's environment, not in the database.
Used only for runs you ask for
A session is decrypted when a run for that tool starts, loaded into a fresh isolated browser, and discarded with it when the run ends.
One sandbox per run
Each agent run gets its own isolated sandbox and browser. Runs do not share state.
Live login is short-lived
The live browser stream is protected by a token issued only to your browser, lasts at most 15 minutes, and is destroyed once you save or cancel.

What the agent may do

Only the task
Each run has one job: read members, invite one person, change one role, or remove one person. The agent is instructed to do that and nothing else.
No shell, no cookie access
The agent has browser controls only. It cannot run commands in its sandbox or read the stored session.
Nothing that costs money without you
A step that would add a paid seat or touch billing pauses the run for your approval. Buttons that look like purchases are also blocked in code until you approve.
Web pages are not instructions
Text on a tool's page is treated as untrusted. The agent is told not to follow instructions it finds there.
Everything is logged
Each run records its steps and a final screenshot, and every change lands in an audit log you can read.

The limits

What you should know before you trust us.

  • Agents act as the account you connect

    Changes appear in each tool's audit log under whichever account you logged in with. We recommend a dedicated admin account per tool, with only the rights needed to manage members: it keeps agent activity separate from yours and limits what the stored session can do. Using your own account works too, where a spare admin seat is not worth paying for.

  • Screens go to an AI model

    To operate a tool, the agent sends what is on the admin page, as text and screenshots, to Anthropic's Claude models through their API. That can include names and email addresses of your team.

  • Agent limits are instructions plus guardrails

    The rules above are enforced by how the agent is prompted and by checks in our code. That is strong, but it is not a formal guarantee that an AI model can never take a wrong step.

  • A breach of us would matter

    If our encryption key and database were both compromised, an attacker could use your stored sessions. You can cut that off at any time by disconnecting a tool here and signing out everywhere in the tool itself.

  • Some tools forbid automation

    A tool's terms may restrict automated use of its interface. Check the terms of what you connect. We use official APIs wherever your plan includes one.

  • No certifications yet

    SmashSSO LLC has no SOC 2 or ISO 27001 report today. If you need one from a vendor, we are not there.

Found a problem? Write to hello@smashsso.com.

Still here? Good. Try it.

Sign in with Google Workspace, connect your tools, and see who has access to what in minutes.

Sign up with Google