Trust

Architecture

Security architecture at a glance

Isolated tenants, scoped action broker, immutable audit log. The AI never holds raw credentials and never talks to a payment provider directly.

01

Ingress

TLS 1.3, WAF, rate limiting, bot filtering and per-tenant request signing on every webhook.

02

Agent runtime

Stateless inference in a per-tenant sandbox. No customer credentials in the model context — only short-lived scoped tokens.

03

Action broker

Every write goes through a policy engine that checks ceiling, eligibility, idempotency key and approval requirements.

04

Audit & retention

Append-only log with actor, policy version, confidence and payload hash. Exportable to SIEM, TTL-controlled per workspace.

Legal

DPA, SCCs and sub-processors

Standard sub-processors

Cloud hostingEU / US
Model inferenceEU / US
Email deliveryIE
Error monitoringDE
Payments & billingIE / US

Customers are notified 30 days before any change. Full list available in the trust center.

Procurement questions we answer every week

Calm modern office space

Need the paperwork today?

Send us your security questionnaire and we'll return it completed, with the SOC 2 report under NDA and a countersigned DPA.