Security Centre

What protects the service—and what still needs independent proof.

This page is for customers, security reviewers and procurement teams. It separates implemented controls, observable operational status and assurance that has not yet been completed.

Implemented safeguards

Controls across identity, data, runtime and operations.

Identity

Protected accounts and roles

Secure sessions, email verification, optional TOTP MFA, workspace roles, tenant checks and SCIM lifecycle controls.

Application

Fail-closed boundaries

CSRF protection, CSP, parameterised database access, rate limits, validated configuration and explicit production readiness.

Runtime

Action control

Versioned policy, idempotent decisions, key revocation and exact-action single-use approvals for material operations.

Evidence

Minimised and traceable

Digests, rule IDs, bounded metadata, signed artifacts, retention controls, deletion receipts and auditable outcomes.

Billing

Verified fulfilment

Signed Stripe webhooks, price and amount binding, idempotency, ordering controls and fail-closed entitlement decisions.

Operations

Readiness and recovery

Managed PostgreSQL, migration checks, protected metrics, transactional email, backup verification and restoration controls.

Data handling

Evaluate content; retain the minimum evidence.

Different product surfaces have different data boundaries. Customers should verify the boundary that applies to their integration.

SurfaceProcessedPersisted
Guided assessmentCustomer answers and assessment contextAnswers, evidence class, findings and result
Hosted GuardSubmitted prompt, output or tool call transientlyDigests, rule IDs, decision, timing and bounded metadata
Local inspectorRepository and configuration on customer machineSigned redacted findings; no source contents or secret values
Controlled red teamAuthorised test interactionsCase outcomes and bounded evidence; no raw hosted transcript
External assurance status

Visible gaps are part of the evidence.

Independent penetration test

Not claimed until an independent engagement is completed and its exact scope and date can be stated.

Formal certification

AgentRiskLayer does not claim ISO, government, regulatory or EU AI Act certification.

Customer responsibility

Customers still need least privilege, secure architecture, network isolation, incident response and human accountability.

Need evidence for review?

Use the public trust routes or contact us with a scoped question.

Security questions should identify the system, feature, data boundary and assurance requirement being reviewed.