Skip to main content

Security, controls and deployment

Shipped, planned, and yours to decide

Read-only access is the default posture, and proposed actions stop at your engineer.
Every row below carries a status label: shipped is not the same as planned.

Content review 2026-07-22 · this page is a statement of practice, not a certification

Control planeread-only accessapproval boundarydeployment

An agreed path, or no path

Five gates, named before evaluation starts: source, credential scope, window, audience, action owner.
Anything outside that agreement stays disconnected.

Every control, with its status

Where a control is not shipped, this table says so rather than implying otherwise.

Security and deployment controls with published status
ControlPublished factStatus
Human approvalProposed remediations — opening a pull request, paging on-call, flipping a feature flag — never execute on the system's own authority: the risk matrix classes all of them high and auto-approves none. A person clears each one, either by approving that single action — which its proposer cannot do — or by issuing a capability grant that pre-authorises a risk class for one investigation, for at most 24 hours and revocable at any time; while such a grant is active, matching remediations execute as they are proposed. Routine alerting and ticket labelling are not remediations: they run automatically on new incidents, and turning the production monitor off stops them.BetaReviewed
Connector accessMinimum credential scopes are agreed per connector before an evidence source is connected. Read-only is the default posture.Customer decisionReviewed
EncryptionNo approved public encryption or key-management commitment is published.Needs reviewReviewed
Retention and deletionNo approved default retention, backup, deletion, or residency policy is published.Needs reviewReviewed
Model and providerProvider behaviour and data-processing terms are confirmed for the chosen deployment before evidence is connected.Customer decisionReviewed
Subprocessor registerA formal public register and notification process are not yet published.PlannedReviewed
RBAC and provisioningRoles carry scoped permissions enforced on every request, and SAML and OIDC single sign-on and SCIM user provisioning are available to closed-beta teams. Group provisioning and role sync from your directory remain roadmap work: SCIM keeps the roster, and role grants stay an administrator action.BetaReviewed
Audit exportAudited actions export as CSV or JSON on demand, and can stream continuously to Splunk, Datadog or your own webhook in OCSF 1.3. A scheduled archival compliance feed remains roadmap work.BetaReviewed
Self-host and customer VPCA Helm install of the same runtime runs inside your own infrastructure today, available to closed-beta teams rather than generally available.BetaReviewed
On-premisesAn on-premises install pins workloads to a region you choose and imports models offline, with a nightly restore drill measuring recovery against a published budget. Available to closed-beta teams.BetaReviewed
Air-gappedA fully disconnected install remains roadmap work, including local-model support, packaged upgrades and support commitments.PlannedReviewed

Self-hosting via Helm

The same runtime installs into your own Kubernetes cluster with a Helm chart, so evidence never leaves your infrastructure.
It is available now to closed-beta teams, not generally available.

Air-gapped and on-premises residency tiers are planned, not shipped.

Your infrastructure · your Kubernetes clusterself-host via HelmBeta
Evidence sources
metric series
application logs
deploy diffs & config
pod & node events
Helm release
Investigation runtime
The engine is identical to the managed service. No specific cloud or execution platform is required.
Cited report + proposed action
stays inside the boundary until a person acts
leaves the cluster
LLM provider — your own keys
or ours, on the managed plans
Managed service

We run the same runtime. The evidence contract, the citations and the approval gate do not change with the hosting choice.

On-premisesBeta

Workloads pinned to a region you choose, models imported offline, nightly restore drill against a published budget.

Air-gappedPlanned

A fully disconnected install — local models, packaged upgrades, support commitments — is roadmap work, not shipped.

4 evidence sources, one runtime · shipped, closed beta and planned never share a box

Questionnaire pack

Reusable answers for a prospect security review. This is current hosted-beta practice, not a certification we hold and not a signed processing agreement.

Security questionnaire pack summary
TopicWhat we can say today
ArchitectureHosted closed beta (Vercel + Supabase + GCP GKE) or the same runtime self-hosted via Helm. Air-gap is planned, not shipped.
Data flowsApproved signal in, cited report out. Remediations stop at a human. OSS dogfood ingests only the two public product repos.
Hosted-beta operatorsVercel, Supabase, Google Cloud, GitHub, and the customer-chosen LLM provider. This is not a formal subprocessor register.
RetentionNo published default retention, backup, deletion, or residency policy. Do not quote a number of days.

Bring your security review before the pilot

We would rather answer the hard questions first than discover them in week six.