Protected accounts and roles
Secure sessions, email verification, optional TOTP MFA, workspace roles, tenant checks and SCIM lifecycle controls.
This page is for customers, security reviewers and procurement teams. It separates implemented controls, observable operational status and assurance that has not yet been completed.
Secure sessions, email verification, optional TOTP MFA, workspace roles, tenant checks and SCIM lifecycle controls.
CSRF protection, CSP, parameterised database access, rate limits, validated configuration and explicit production readiness.
Versioned policy, idempotent decisions, key revocation and exact-action single-use approvals for material operations.
Digests, rule IDs, bounded metadata, signed artifacts, retention controls, deletion receipts and auditable outcomes.
Signed Stripe webhooks, price and amount binding, idempotency, ordering controls and fail-closed entitlement decisions.
Managed PostgreSQL, migration checks, protected metrics, transactional email, backup verification and restoration controls.
Different product surfaces have different data boundaries. Customers should verify the boundary that applies to their integration.
| Surface | Processed | Persisted |
|---|---|---|
| Guided assessment | Customer answers and assessment context | Answers, evidence class, findings and result |
| Hosted Guard | Submitted prompt, output or tool call transiently | Digests, rule IDs, decision, timing and bounded metadata |
| Local inspector | Repository and configuration on customer machine | Signed redacted findings; no source contents or secret values |
| Controlled red team | Authorised test interactions | Case outcomes and bounded evidence; no raw hosted transcript |
Not claimed until an independent engagement is completed and its exact scope and date can be stated.
AgentRiskLayer does not claim ISO, government, regulatory or EU AI Act certification.
Customers still need least privilege, secure architecture, network isolation, incident response and human accountability.