Security & trust

The wall isn't a metaphor. It's the product.

Every decision in our deployment framework starts from the same question: what's the least access an agent needs to do its job? Here's how that plays out in practice.

Encryption everywhere

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256, across every deployment model we offer.

Least-privilege by default

Agents are provisioned with the minimum scope required for their task. Broader access is a deliberate policy decision, never a default.

No training on your data

Nothing you send through your deployment is used to train a model — ours or any third-party model we call — and it's never shared across customers.

Immutable audit logs

Every agent action is written to an append-only log with a timestamp and the policy it was checked against. Logs are exportable for your own compliance review.

Human approval gates

Your policy defines which actions require sign-off. Anything outside that scope pauses for a person instead of executing.

Private VPC & self-hosted

Every deployment runs inside your own cloud environment, by default — not just as an enterprise option — for full data residency and network isolation.

Compliance posture

Honest about where we are

We'd rather tell you exactly what's certified today than let a badge do the talking.

Formal certifications (SOC 2, ISO)None yet — early-stage company
Encryption in transit & at restStandard, all plans
Private VPC / self-hosted deploymentEnterprise plan
Security disclosure contact[email protected]

Responsible disclosure

Found a security issue?

We take reports from independent researchers seriously and will always work with you in good faith. Email [email protected] with details — please don't test against live customer data or attempt to access data that isn't yours. Our security.txt file has the same contact details in the standard machine-readable format security researchers' tools look for.

Common questions

What security teams ask us first

No, not yet. We're an early-stage company and haven't pursued formal certification. What we can show you is exactly how the platform enforces least-privilege access, approval gates, and audit logging, and walk through the architecture directly on a call.

By default, data is encrypted at rest and in transit on our standard cloud infrastructure. Enterprise customers can choose a private VPC or self-hosted deployment for full data residency and network isolation control.

Yes, with advance coordination so we can distinguish your test traffic from a real incident. Contact [email protected] to schedule one.

You can export your full configuration and audit logs at any time. Since your deployment runs inside your own environment, cancellation just means we lose access — your data was never on our systems to begin with.

Bring your security team to the next call.

We'd rather answer the hard questions on the diagnostic call than after you've already committed.

Book a diagnostic call