Buyer assurance centre
Evidence security and procurement can verify.
Architecture, data handling, runtime boundaries, executable validation and external-proof status. Implemented means source and tests exist; pending means an independent party or production history is still required.
Evaluate content; retain evidence.
- Hosted Guard: processes submitted content transiently and stores decisions, digests and rule IDs.
- No raw persistence: prompts, responses and tool arguments are excluded from runtime event records.
- Local option: customer-operated gateway keeps traffic inside the customer environment.
- Retention: plan-bound event purging with account export and deletion.
Controlled access
- Five server-enforced workspace roles.
- MFA and reauthentication for sensitive account actions.
- One-time API key reveal, hash-only storage, expiry and immediate revocation.
- SCIM provisioning and deprovisioning.
Know what changed
- Agent, model, MCP, tool, vector-store and gateway inventory.
- Stable identities and repeated asset snapshots.
- Public, privileged and production exposure classification.
- Risk-increasing drift changes the deployment gate to review required.
Trace every security decision
- Policy versions, API keys, inventory and remediation audit trail.
- Signed Slack/Jira/HTTPS events plus CEF, OCSF and SARIF exports.
- Protected Prometheus metrics and database readiness checks.
- PostgreSQL backup, checksum verification and controlled restore tooling.
Procurement truth table
No vague questionnaire answers.
Internal validation proves packaged behaviour under the tested conditions. It does not create independent assurance.
Hosted runtime enforcementImplementedProject keys, policy versions, idempotency, quotas and privacy-safe events.
Tenant isolationImplementedWorkspace authorization and cross-tenant denial tests.
Managed PostgreSQL recoveryImplementedNative migrations, backup verification and atomic restore commands.
Independent penetration testExternal pendingMust be performed against the deployed service by an independent tester.
SOC 2 / ISO 27001External pendingNot claimed.
Production SLA and detection historyBeta pendingRequires live operation and measured customer outcomes.
Controlled beta
Start with one measurable security boundary.
Create the project, enforce the policy and collect the evidence before expanding.