Buyer assurance centre

Evidence security and procurement can verify.

Architecture, data handling, runtime boundaries, executable validation and external-proof status. Implemented means source and tests exist; pending means an independent party or production history is still required.

Automated tests86/86Including hosted-control-plane contracts
Detection benchmark20/20Limited transparent synthetic cases
Safety scenarios1,000/1,000Internal deterministic validation
External certificationPendingNever represented as complete
Runtime privacy

Evaluate content; retain evidence.

  • Hosted Guard: processes submitted content transiently and stores decisions, digests and rule IDs.
  • No raw persistence: prompts, responses and tool arguments are excluded from runtime event records.
  • Local option: customer-operated gateway keeps traffic inside the customer environment.
  • Retention: plan-bound event purging with account export and deletion.
Identity and keys

Controlled access

  • Five server-enforced workspace roles.
  • MFA and reauthentication for sensitive account actions.
  • One-time API key reveal, hash-only storage, expiry and immediate revocation.
  • SCIM provisioning and deprovisioning.
AI inventory

Know what changed

  • Agent, model, MCP, tool, vector-store and gateway inventory.
  • Stable identities and repeated asset snapshots.
  • Public, privileged and production exposure classification.
  • Risk-increasing drift changes the deployment gate to review required.
Operational assurance

Trace every security decision

  • Policy versions, API keys, inventory and remediation audit trail.
  • Signed Slack/Jira/HTTPS events plus CEF, OCSF and SARIF exports.
  • Protected Prometheus metrics and database readiness checks.
  • PostgreSQL backup, checksum verification and controlled restore tooling.
Procurement truth table

No vague questionnaire answers.

Internal validation proves packaged behaviour under the tested conditions. It does not create independent assurance.

Hosted runtime enforcementImplementedProject keys, policy versions, idempotency, quotas and privacy-safe events.
Tenant isolationImplementedWorkspace authorization and cross-tenant denial tests.
Managed PostgreSQL recoveryImplementedNative migrations, backup verification and atomic restore commands.
Independent penetration testExternal pendingMust be performed against the deployed service by an independent tester.
SOC 2 / ISO 27001External pendingNot claimed.
Production SLA and detection historyBeta pendingRequires live operation and measured customer outcomes.
Controlled beta

Start with one measurable security boundary.

Create the project, enforce the policy and collect the evidence before expanding.