Trust Center
Security architecture, encryption, IAM, and responsible AI controls for enterprise buyers.
Security architecture
Separated control and data planes, least-privilege service identities, and defense-in-depth across API, console, and runners.
Encryption
TLS 1.2+ in transit. AES-256 at rest. Customer-managed keys (CMK) available for self-hosted and enterprise cloud.
IAM, RBAC, SSO & MFA
SAML/OIDC SSO, enforced MFA options, org and project roles, service accounts, and just-in-time access patterns.
Secrets
Vault-backed secrets with rotation, scoped injection into jobs/notebooks, and audit on every read.
Network security
IP allowlists, Private Link roadmap, egress controls for runners, and continuous exposure scanning.
Responsible AI
Human approval for high-risk agent actions, prompt/tool logging, evaluation harnesses, and abuse monitoring.
Data residency
Pin customer content and control-plane metadata to US, EU, or India regions. Cross-border transfers use SCCs where required.
Infrastructure security
Hardened API runtimes, private networking options, secrets rotation, and continuous exposure scanning.
Downloadable compliance reports
Machine-readable readiness packs for security questionnaires and procurement.
Control mapping and evidence summary for enterprise security review.
ISMS Annex A control readiness for SaaS operations.
Safeguard mapping for BAA-eligible deployments.
Processor obligations, DSR support, and residency controls.
Transit, at-rest, and CMK posture.
Supported regions and pin options.
Human-in-the-loop and evaluation controls.
Network, secrets, and runtime hardening summary.
Need a signed evidence pack?
Project admins can mint HMAC-signed Trust packs from Governance → Signed Artifacts. Full SOC 2 reports remain available under NDA.