Skip to content

Security

Summary

Where things run, who can reach them, and what is recorded.

Deployments run inside your environment or a dedicated tenant. Permissions are inherited from your directory and are never widened by the OS.

Sections

What this page will cover.

Deployment model and data boundaries
Identity and access
Read paths and write paths
Audit and retention
Model providers and data handling
Certifications and current status
Reporting a vulnerability

Certification status will be stated accurately when published. If a certification is in progress it will say in progress. No badge is displayed that has not been issued.

The line that matters

Reading a system is not permission to change it.

Read access and write access are declared separately for every agent and every system. An agent that can read a system does not thereby have permission to change it.

Plate data

Deployment
Your environment
Paths
Read and write separate
Status
Draft pending counsel
READ NEXT · 04

Read next.

Company
Who we are and why the architecture is public.
For enterprises
Deployment model, permissions and audit.
Talk to us
A person reads what you write.

One architecture. Twenty pages. Same document.

TALK TO US · 05

A question about any of this?

Write to us. Enterprise deployments are governed by a separate agreement, and we are happy to walk through it.

Talk to us

A conversation, not a demo script. We ask what your systems of record are, what they cannot answer, and which decisions actually matter. If an Industry OS is not the right answer for you, we will say so.