Trust built in, not bolted on.

Governance, compliance, and audit are primitives in the platform — engineered into every layer. Here's what that looks like in practice.

Compliance posture

Where we stand on the frameworks you care about.

Statuses reflect current posture across standards most relevant to our buyers. Detailed documentation available on request under NDA.

ITAR
Deployment-readyInternational Traffic in Arms Regulations — U.S. export controls for defense-related technical data.
SOC 2 Type I
In progressSystem and Organization Controls 2 — an independent audit proving we keep customer data secure over time. Type I is in progress, with Type II certification to follow over the coming months.
FedRAMP Moderate
On roadmapFederal Risk and Authorization Management Program — the U.S. government's security bar for cloud services handling federal data.
CMMC Level 2
On roadmapCybersecurity Maturity Model Certification — the Defense Department's standard for handling controlled information.
HIPAA
MappedHealth Insurance Portability and Accountability Act — U.S. rules for protecting patient health information.
FERPA
MappedFamily Educational Rights and Privacy Act — U.S. law protecting the privacy of student education records.
Section 508 / WCAG 2.1 AA
MappedU.S. accessibility law (Section 508), aligned to the Web Content Accessibility Guidelines — so the product works for people with disabilities.
NIST 800-53 / 800-171
MappedNational Institute of Standards and Technology control catalogs — federal security controls for protecting sensitive systems and data.

Status vocabulary, by readiness: Deployment-ready · In progress · On roadmap · Mapped. Specifics available in the security packet under NDA.

Security controls

The controls monitored across our program.

Continuously evidenced through Drata, our compliance platform. Full reports and live status are available in our Trust Center under NDA.

Controls
65
Implemented
61
In progress
4
ImplementedIn progress

Product Security

  • ImplementedAudit Logging
  • ImplementedData Security
  • ImplementedIntegrations
  • ImplementedMulti-Factor Authentication
  • ImplementedRole-Based Access Control

Reports

  • ImplementedOther Reports
  • In progressPentest Report
  • In progressSOC 2 Report

Data Security

  • ImplementedAccess Monitoring
  • ImplementedData Asset Classification
  • ImplementedData Backups
  • ImplementedEncryption-at-rest
  • ImplementedEncryption-in-transit

App Security

  • In progressApplication Penetration Testing
  • In progressSecure Development Training
  • ImplementedSoftware Development Lifecycle
  • ImplementedVulnerability & Patch Management
  • ImplementedWeb Application Firewall

AI

  • ImplementedAI Security
  • ImplementedThird-Party AI Diligence
  • ImplementedEmployee AI Usage

Data Privacy

  • ImplementedData Breach Notifications
  • ImplementedData Privacy Officer
  • ImplementedEmployee Privacy Training

Access Control

  • ImplementedAccess Log Management
  • ImplementedAutomated Account Management
  • ImplementedData Access
  • ImplementedDevice Lock
  • ImplementedInternal Single-Sign-On (SSO)

Infrastructure

  • ImplementedStatus Monitoring
  • ImplementedAmazon Web Services
  • ImplementedAnti-DDoS
  • ImplementedBC/DR

Endpoint Security

  • ImplementedAnti-Malware
  • ImplementedDisk Encryption
  • ImplementedDNS Filtering
  • ImplementedEndpoint Detection & Response
  • ImplementedHost Intrusion Detection System (HIDS)

Network Security

  • ImplementedFirewall
  • ImplementedSecurity Information and Event Management
  • ImplementedWeb Application Firewall

Policies

  • ImplementedAcceptable Use Policy
  • ImplementedAccess Control Policy
  • ImplementedInformation Security Policy
  • ImplementedVendor Management Policy
  • ImplementedVulnerability Management Policy

Incident Response

  • ImplementedDesignated Response Personnel
  • ImplementedIncident Reporting Process

Risk Management

  • ImplementedData Access/Impact Levels
  • ImplementedRisk Assessments

Training

  • ImplementedEmployee Privacy Training
  • ImplementedSecurity Awareness Training

Continuous Monitoring

  • ImplementedAutomated Alert Response
  • ImplementedAutomated Compliance Monitoring
  • ImplementedEvent & Audit Log Management
  • ImplementedFile Integrity Monitoring (FIM)
  • ImplementedSecurity Information & Event Management (SIEM)

Security practices

The controls every deployment inherits.

Auth inheritance

Agents respect your existing identity and access model. Users only see what they're authorized to see — enforced at every call.

PII boundaries

Declarative boundaries keep sensitive fields inside your perimeter. Every third-party call is explicit, logged, and policy-gated.

Encryption at rest + in transit

TLS 1.3 everywhere. AES-256 at rest. Keys managed in Vault Transit / Azure Key Vault / AWS KMS — your choice.

WORM audit

Every agent action is cryptographically signed and written to tamper-evident WORM storage. Independently verifiable by regulators.

HITL + kill switch

Risk-scored actions route to human approvers before execution. Circuit-breaker kill switch for emergency bulk revocation.

Continuous compliance

Our security controls are continuously monitored and evidenced through Drata, our compliance platform. Current reports and audit status are available in our Trust Center under NDA.

Data handling

Your data, on your terms.

Data residency

Deploy in the region and perimeter you require. GovCloud, customer VPC, on-prem, or air-gapped — the runtime is the same.

Retention & deletion

Configurable retention per data class. Right-to-delete honored end-to-end, including derived embeddings and audit-safe tombstones.

Sub-processor transparency

Current sub-processor list shared on request. Changes communicated in advance with opt-out for deployments that require it.

Need the security packet?

SOC 2 reports, penetration-test results, security-questionnaire responses, and data-flow diagrams ship under NDA. Reach out and we'll share within one business day.