Trust center

Everything auditors and procurement ask for, in one place.

Security posture, subprocessors, audit status, the certification roadmap, and the disclosure policy. Bookmark this URL. We update it as state changes, not when a sales cycle requires it.

Planned

SOC 2 Type II

Target Q1 2027

Planned, not yet started: no auditor engaged, observation window not begun. We will publish the firm name and the date the report becomes available once underway.

Planned

HIPAA BAA

With SOC 2 cutover

Planned; the report and BAA are not yet available. Healthcare deployments require the BAA; we are not signing one before it exists.

Preparing

CSA STAR for AI

Submission in preparation

Preparing a CSA STAR for AI submission; not yet filed. Independent CSA review aligned with the Agentic Control Plane working group.

Security posture

The shortlist. Full security page →

Hybrid-signed (Ed25519 + ML-DSA-65) Decision Receipts

Every gateway action signed. Publicly verifiable, offline, with any compliant library.

BYO-keys with no-persistence

Provider keys sent on X-Provider-Key are forwarded upstream and never written to any database.

Hashed-only license storage

License keys live as SHA-256 hashes. Issued once at provisioning; never re-issued.

HMAC-verified inbound webhooks

Signatures are constant-time compared, with a 5-minute replay window.

Tenant scoping on receipt and grant reads

Receipt and grant reads carry a tenant_id predicate in SQL, with revocation checked in depth.

HTTP-only session cookies

Portal sessions stored HTTP-only, SameSite=Lax. No JS-side reads.

Configurable retention

Receipts 365d default; cache 30d; embeddings 90d. LRU eviction on size caps.

Anti-relay-aware proxy

Byte-identical forwarding when needed. Body-mutating features auto-disable for OAuth tokens.

Subprocessors

Who touches data on our behalf.

AWS

Primary cloud infrastructure

us-west-1

Paddle

Merchant of record · billing

EU + US

Anthropic / OpenAI / Groq

LLM inference (tenant keys, never persisted)

Per provider

Customers may pin to a subset via Enterprise tier. Region-pinning available with the GDPR data-residency module (planned · Enterprise).

Vulnerability disclosure

Found something? Tell us.

Email via the contact form with reproducer details. We acknowledge within two business days and aim to triage within one week. Coordinated disclosure is welcome; we will agree a public-write-up date together.

A formal bug-bounty program (HackerOne, scoped) is on the roadmap concurrent with the SOC 2 Type II cutover. Until then, researcher acknowledgement is by name on this page on request.

Procurement questionnaire?

We fill in security questionnaires directly. No NDA gate, no sales detour. Email your spec and we will return a completed copy.