Skip to main content

Security, controls and deployment

What is shipped, what is planned, and what is yours to decide

Read-only access is the default posture and proposed actions stop at your engineer.
Everything below carries a status label, because a security page that blurs roadmap into availability is worse than no security page.

Content review 2026-07-22 · this page is a statement of practice, not a certification

Control planeread-only accessapproval boundarydeployment

Evidence moves only through an agreed path

An evaluation starts by naming the source, the credential scope, the purpose, the report audience, and the person who owns the next action.
Anything outside that written agreement stays disconnected.

  1. 01An evidence source you approve
  2. 02A minimum scoped, read-only credential
  3. 03A bounded investigation window
  4. 04A cited report
  5. 05A human approval boundary

The published status of every control

Where a control is not shipped, this table says so rather than implying otherwise.

Security and deployment controls with published status
ControlPublished factStatus
Human approvalProposed actions remain subject to engineer review. There is no autonomous remediation path.BetaReviewed
Connector accessMinimum credential scopes are agreed per connector before an evidence source is connected. Read-only is the default posture.Customer decisionReviewed
EncryptionNo approved public encryption or key-management commitment is published.Needs reviewReviewed
Retention and deletionNo approved default retention, backup, deletion, or residency policy is published.Needs reviewReviewed
Model and providerProvider behaviour and data-processing terms are confirmed for the chosen deployment before evidence is connected.Customer decisionReviewed
Subprocessor registerA formal public register and notification process are not yet published.PlannedReviewed
RBAC and provisioningGranular roles, SSO and provisioning remain roadmap work.PlannedReviewed
Audit exportFormal audit export and SIEM streaming remain roadmap work.PlannedReviewed
Self-host and customer VPCA Helm install of the same runtime runs inside your own infrastructure today, available to closed-beta teams rather than generally available.BetaReviewed
On-premisesAn on-premises install pins workloads to a region you choose and imports models offline, with a nightly restore drill measuring recovery against a published budget. Available to closed-beta teams.BetaReviewed
Air-gappedA fully disconnected install remains roadmap work, including local-model support, packaged upgrades and support commitments.PlannedReviewed

Self-hosting via Helm

The same investigation runtime installs into your own Kubernetes cluster with a Helm chart, so evidence never leaves your infrastructure.
It is available now to closed-beta teams — not generally available, and the page will say so on the day that changes.

Air-gapped and on-premises residency tiers are planned, not shipped.

Talk to sales

Bring your security review before the pilot

We would rather answer the hard questions first than discover them in week six.