Security & trust
The wall isn't a metaphor. It's the product.
Every decision in our deployment framework starts from the same question: what's the least access an agent needs to do its job? Here's how that plays out in practice.
Encryption everywhere
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256, across every deployment model we offer.
Least-privilege by default
Agents are provisioned with the minimum scope required for their task. Broader access is a deliberate policy decision, never a default.
No training on your data
Nothing you send through your deployment is used to train a model — ours or any third-party model we call — and it's never shared across customers.
Immutable audit logs
Every agent action is written to an append-only log with a timestamp and the policy it was checked against. Logs are exportable for your own compliance review.
Human approval gates
Your policy defines which actions require sign-off. Anything outside that scope pauses for a person instead of executing.
Private VPC & self-hosted
Every deployment runs inside your own cloud environment, by default — not just as an enterprise option — for full data residency and network isolation.
Compliance posture
Honest about where we are
We'd rather tell you exactly what's certified today than let a badge do the talking.
| Formal certifications (SOC 2, ISO) | None yet — early-stage company |
| Encryption in transit & at rest | Standard, all plans |
| Private VPC / self-hosted deployment | Enterprise plan |
| Security disclosure contact | [email protected] |
Responsible disclosure
Found a security issue?
We take reports from independent researchers seriously and will always work with you in good faith. Email [email protected] with details — please don't test against live customer data or attempt to access data that isn't yours. Our security.txt file has the same contact details in the standard machine-readable format security researchers' tools look for.
Common questions
What security teams ask us first
No, not yet. We're an early-stage company and haven't pursued formal certification. What we can show you is exactly how the platform enforces least-privilege access, approval gates, and audit logging, and walk through the architecture directly on a call.
By default, data is encrypted at rest and in transit on our standard cloud infrastructure. Enterprise customers can choose a private VPC or self-hosted deployment for full data residency and network isolation control.
Yes, with advance coordination so we can distinguish your test traffic from a real incident. Contact [email protected] to schedule one.
You can export your full configuration and audit logs at any time. Since your deployment runs inside your own environment, cancellation just means we lose access — your data was never on our systems to begin with.