Security & Trust

Autonomy requires absolute safety.

When agents run your business, security isn't just about protecting data—it's about protecting operations. Our architecture ensures agents act strictly within your boundaries.

Blast radius limits

Caps on what any agent can do per transaction and per day. Limits are strictly enforced at the platform level, preventing runaway actions even if an agent hallucinates.

Approval gates

Irreversible actions wait for your one-tap approval. You configure which actions require human oversight before execution.

Kill switch

One button stops all agents instantly. SMS 'STOP' from anywhere to immediately halt all agent activity across your entire business.

Complete audit log

Every action by every agent, logged forever. Complete traceability for all decisions, communications, and transactions.

Sandboxed access

Each agent can only touch what its role requires. Enforced at the credential layer — agents retrieve logins from a vault you own (Bitwarden or LastPass) with per-agent, revocable access.

Per-tenant isolation

Your agents serve you. Period. No agent ever works for two businesses. Your data is isolated and never used to train models for other customers.

Encryption

Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). We use industry-standard encryption to protect your most sensitive business information.

Rate limits & circuit breakers

Every agent has per-tool and global rate limits. If daily costs exceed 3x your average, the platform pauses the most expensive agents and alerts you — a runaway loop can never become a runaway bill.

Compliance & Standards

We build to the highest enterprise standards, ensuring your AI workforce meets all regulatory requirements for your industry. All AI inference runs on US-resident endpoints under business associate agreements — your data is never processed offshore.

US Data Residency
SOC 2 Type II (in progress)
GDPR Compliant
CCPA Compliant
HIPAA Ready (Phase 3)

SOC 2 status.

A live view of where we are on our path to SOC 2 Type II. We publish this so you don't have to ask.

Phase 1 · Security policy framework

complete

Information security, access control, incident response, vendor management policies in place.

Phase 2 · Controls implementation

complete

Audit logging, MFA enforcement, least-privilege access, endpoint management deployed.

Phase 3 · Type I report

in progress

Auditor engaged. Type I attestation expected Q3.

Phase 4 · Type II observation period

upcoming

Six-month observation window begins after Type I. Type II report expected the following year.

Sub-processors.

The third-party services we use to deliver Sentica. Each one is reviewed, contracted with a DPA, and audited for your tenant's data exposure.

Sub-processor
Purpose
Data region
AWS
Compute, storage, networking
US-East / US-West
AWS Bedrock / Azure AI Foundry
LLM inference — open-weight models, US regions (no training on customer data)
US
Anthropic
LLM inference — US-hosted endpoint (no training on customer data)
US
Stripe
Payment processing (when used by agents)
US / EU
Twilio
Voice & SMS infrastructure (when used by agents)
US
Cloudflare
DNS, DDoS protection, WAF
Global edge

We notify customers at least 30 days before adding a new sub-processor that handles customer data.

Security resources.