Trust built in, not bolted on.
Governance, compliance, and audit are primitives in the platform — engineered into every layer. Here's what that looks like in practice.
Compliance posture
Where we stand on the frameworks you care about.
Statuses reflect current posture across standards most relevant to our buyers. Detailed documentation available on request under NDA.
Status vocabulary, by readiness: Deployment-ready · In progress · On roadmap · Mapped. Specifics available in the security packet under NDA.
Security controls
The controls monitored across our program.
Continuously evidenced through Drata, our compliance platform. Full reports and live status are available in our Trust Center under NDA.
- Controls
- 65
- Implemented
- 61
- In progress
- 4
Product Security
- ImplementedAudit Logging
- ImplementedData Security
- ImplementedIntegrations
- ImplementedMulti-Factor Authentication
- ImplementedRole-Based Access Control
Reports
- ImplementedOther Reports
- In progressPentest Report
- In progressSOC 2 Report
Data Security
- ImplementedAccess Monitoring
- ImplementedData Asset Classification
- ImplementedData Backups
- ImplementedEncryption-at-rest
- ImplementedEncryption-in-transit
App Security
- In progressApplication Penetration Testing
- In progressSecure Development Training
- ImplementedSoftware Development Lifecycle
- ImplementedVulnerability & Patch Management
- ImplementedWeb Application Firewall
AI
- ImplementedAI Security
- ImplementedThird-Party AI Diligence
- ImplementedEmployee AI Usage
Data Privacy
- ImplementedData Breach Notifications
- ImplementedData Privacy Officer
- ImplementedEmployee Privacy Training
Access Control
- ImplementedAccess Log Management
- ImplementedAutomated Account Management
- ImplementedData Access
- ImplementedDevice Lock
- ImplementedInternal Single-Sign-On (SSO)
Infrastructure
- ImplementedStatus Monitoring
- ImplementedAmazon Web Services
- ImplementedAnti-DDoS
- ImplementedBC/DR
Endpoint Security
- ImplementedAnti-Malware
- ImplementedDisk Encryption
- ImplementedDNS Filtering
- ImplementedEndpoint Detection & Response
- ImplementedHost Intrusion Detection System (HIDS)
Network Security
- ImplementedFirewall
- ImplementedSecurity Information and Event Management
- ImplementedWeb Application Firewall
Policies
- ImplementedAcceptable Use Policy
- ImplementedAccess Control Policy
- ImplementedInformation Security Policy
- ImplementedVendor Management Policy
- ImplementedVulnerability Management Policy
Incident Response
- ImplementedDesignated Response Personnel
- ImplementedIncident Reporting Process
Risk Management
- ImplementedData Access/Impact Levels
- ImplementedRisk Assessments
Training
- ImplementedEmployee Privacy Training
- ImplementedSecurity Awareness Training
Continuous Monitoring
- ImplementedAutomated Alert Response
- ImplementedAutomated Compliance Monitoring
- ImplementedEvent & Audit Log Management
- ImplementedFile Integrity Monitoring (FIM)
- ImplementedSecurity Information & Event Management (SIEM)
Security practices
The controls every deployment inherits.
Auth inheritance
Agents respect your existing identity and access model. Users only see what they're authorized to see — enforced at every call.
PII boundaries
Declarative boundaries keep sensitive fields inside your perimeter. Every third-party call is explicit, logged, and policy-gated.
Encryption at rest + in transit
TLS 1.3 everywhere. AES-256 at rest. Keys managed in Vault Transit / Azure Key Vault / AWS KMS — your choice.
WORM audit
Every agent action is cryptographically signed and written to tamper-evident WORM storage. Independently verifiable by regulators.
HITL + kill switch
Risk-scored actions route to human approvers before execution. Circuit-breaker kill switch for emergency bulk revocation.
Continuous compliance
Our security controls are continuously monitored and evidenced through Drata, our compliance platform. Current reports and audit status are available in our Trust Center under NDA.
Data handling
Your data, on your terms.
Data residency
Deploy in the region and perimeter you require. GovCloud, customer VPC, on-prem, or air-gapped — the runtime is the same.
Retention & deletion
Configurable retention per data class. Right-to-delete honored end-to-end, including derived embeddings and audit-safe tombstones.
Sub-processor transparency
Current sub-processor list shared on request. Changes communicated in advance with opt-out for deployments that require it.
Need the security packet?
SOC 2 reports, penetration-test results, security-questionnaire responses, and data-flow diagrams ship under NDA. Reach out and we'll share within one business day.