Credentials live in the session container.
A credential is passed into one session. It is scoped to the targets you declare. It never reaches another session, another customer, or your device.
Every session is fresh, isolated, and gone on close. This page states our posture plainly: what we hold, what we destroy, and how to verify it.
Our SOC 2 Type II audit is in progress. Controls are tracked in Vanta. We share control detail and questionnaire responses on request for enterprise evaluation.
This is our only compliance claim. We do not list certifications we do not hold.
A credential enters one container, does one job, and dies with it. Three guarantees define the boundary.
A credential is passed into one session. It is scoped to the targets you declare. It never reaches another session, another customer, or your device.
When the session closes, the container is destroyed. Cookies, tokens, and the credentials inside go with it. They are not written to logs.
A persistent session keeps state between runs. That state is an encrypted blob under your key. We cannot read it without you.
We retain nothing you did not ask us to keep. Disposal is the rule, not a setting you turn on.
Every session is destroyed when it ends. The container, its memory, and its storage are gone. There is no snapshot to recover.
By default no page content, no session state, and no credentials survive the session. Persistence is opt-in, per session, under your key.
Legba is built for access the end user has agreed to. Account access, authorized automation, and security testing on assets you own or are permitted to test.
You hold explicit consent from the user whose access you drive. We enforce this at onboarding. Use outside that scope is not permitted.
Read our disclosure policy at /.well-known/security.txt. For security questions, reach us at support@legba.app or through contact.
Legba is a disposable real browser: it spawns a clean session, does the work, and destroys itself on close.
chromium / real fingerprint · residential ip · burn on close
Real browser. Real IP. Real page. Spawn a session. Do the work. Destroy it. Off your device. Off your stack. Gone on close.