Trust
An honest account of where security posture stands today.
This page states what is true now and what is planned. We do not claim certifications or compliance standards that haven't been completed.
What we do today
Current practices.
Deployment boundaries
The platform is designed to run inside your cloud account and data boundary rather than a shared environment. See Deployment for the reference architecture.
Access control
Connections use credentials scoped to what a specific agent needs, configured per engagement rather than granted broadly by default.
Logging & traceability
Agent actions, tool calls, policy decisions, and human approvals are recorded in a trace, so a completed workflow can be reconstructed after the fact.
Human review
Actions above a defined risk threshold route to a named reviewer before they execute, rather than completing unattended.
Data handling
{{TBD: data retention period, encryption at rest/in transit details, and data processing locations to be confirmed and published here.}}
What is on the roadmap
Not yet in place.
- Formal third-party security certification (e.g. SOC 2) — not yet completed.
- Independent penetration testing program — not yet completed.
- Published subprocessor list with update notifications.
- Expanded self-serve documentation for security and compliance reviewers.
Subprocessors & DPA
Who else touches the data.
{{TBD: current subprocessor list to be published here.}} A data processing agreement is available for engagements that require one — see the DPA page.
{{TBD: data residency options and current maturity statement to be confirmed by legal/security before publishing region-specific commitments.}}
Security review before a pilot?
Bring your questionnaire — a working session is a faster way to work through it than an email thread.
