Credential Handling Acknowledgment
1. Overview
This document describes how the IronFist AI platform handles API keys, OAuth tokens, and other credentials you provide during onboarding and ongoing use. By proceeding with deployment, you acknowledge and accept these practices.
2. How Credentials Are Stored
All credentials you provide are stored in your dedicated Azure Key Vault instance ({your-tenant}-agent-kv). Azure Key Vault uses Microsoft-managed encryption keys with FIPS 140-2 Level 2 validated cryptographic modules on the underlying storage infrastructure. Credentials are encrypted at rest (AES-256) and in transit (TLS 1.2+). Access is restricted via Azure RBAC to your agent's managed identity only.
Credentials stored include: your Anthropic API key, communication channel tokens (Telegram bot token, webhook API key), OAuth client IDs and secrets for Google and Microsoft integrations, and any additional API keys for optional integrations (GitHub, Browserbase, ElevenLabs, OpenAI).
3. Who Accesses Your Credentials
Only your agent's managed identity has runtime access to your Key Vault. StableState's admin panel does not display credential values. StableState engineers do not have routine access to your Key Vault. Access is logged and auditable.
4. Tenant Isolation
Your Key Vault is scoped to your Azure resource group. Your agent's managed identity has RBAC access only to your resources. No other subscriber's agent, managed identity, or infrastructure can access your Key Vault. There is no shared credential storage across tenants.
5. Your Responsibilities
You are responsible for: the validity and scope of all API keys and credentials you provide, ensuring your API keys have sufficient credits, quotas, and permissions, revoking or rotating credentials when you suspect compromise, understanding that your agent makes API calls using your credentials and you bear the costs and consequences, and compliance with the terms of service of each third-party provider whose credentials you supply (Anthropic, Google, Microsoft, GitHub, Browserbase, etc.).
6. Key Rotation
You may rotate any credential at any time via the dashboard credential manager. Updated credentials take effect within 5 minutes as your agent refreshes its integration list periodically. StableState recommends rotating credentials if you suspect unauthorized access, at least every 12 months as a security best practice, and immediately if a third-party provider notifies you of a breach.
7. Acknowledgment
Questions about this document?
Contact us at [email protected]
Visit https://www.stablestateit.com for general inquiries and our contact form.
