Everything your security and risk teams will ask for.
Agents are actors, not applications: they read untrusted content and act inside your estate. This is how we make that safe, and the evidence, controls and documents your homologation needs, in one place.
How we keep an actor safe
An agent is an actor. It gets actor controls.
Agents get their own identity
No agent borrows a human token or a shared service account. Each runs under a short-lived, least-privilege non-human identity, so a stolen agent credential is worth almost nothing.
Untrusted input can never become instruction
Prompt injection is contained structurally, not by a classifier: a taint boundary (a dual-LLM / CaMeL pattern) keeps content the agent reads from ever steering what it does.
Least-privilege, typed capabilities
An agent's blast radius is only the capabilities it holds. Capabilities are typed and scoped; egress is deny-by-default behind an allow-list, so data cannot be pointed at an attacker's destination.
Autonomy is earned, and reversible
Every process starts in Shadow Mode and climbs L0–L4 only through measured evals. A tested, logged kill-switch and drift monitoring can demote an agent automatically when it moves off the bar.
An audit trail a regulator can inspect
Every consequential step is journaled append-only and hash-chained, written before the action commits, fail-closed. Any decision can produce its full chain, under which policy version, on what data, by which actor.
The regulated decision stays yours
Where the law or your risk committee requires a human, the agent prepares, verifies and orchestrates, but never decides. REQUIRE-HUMAN is a wired verdict, not a guideline.
Deployment & sovereignty
Your data stays where the law requires
Provider-agnostic and deploy-anywhere: Anthropic, Mistral, or open-source on your own GPUs, inside your VPC, on-premises, or fully air-gapped, with confidential computing / TEEs where you need them. Routing is sensitivity-based, so regulated and personal data can stay on-prem while less-sensitive work uses managed models. Portable and exit-ready by contract.
- Deploy topologyVPC · on-premises · air-gapped · TEEs
- Model routingProvider-agnostic, sensitivity-based
- Data residencyEU / in-perimeter, your control
- ExitPortable, escrow, no lock-in
For your review
The documents your homologation needs.
Available under NDA / DPA. Ask and we'll route the right pack to your security and risk teams.
Data Processing Agreement (DPA)
Standard DPA with SCCs, available for review.
ISO 27001 / 27017 / 27018 certificates
Current certificates on request.
Security overview & OWASP ASI mapping
Controls mapped to ASI01–10, per engagement.
Sub-processor list
Provided under DPA; most deployments run inside your perimeter.
EU AI Act conformity notes
Risk-tier placement and Article-by-control mapping for the use case.
Honest read before scope
Talk to us about your homologation.
Bring the process and the controls your risk committee needs to sign. We will give you an honest read on what an agent can do, where the human stays, and what evidence you would hold, before anyone talks scope.
