NewInteractive Agents Live

Domain Experts view

Compliance by architecture. Defendable to any auditor.

Encryption, identity, and a documented posture your security team can review under NDA. Because the controls live inside the agent itself, the evidence an auditor asks for is the same record the system already keeps.

Audit trailrefund-agent · prod
Recording
  1. Policy applied

    KYC threshold, automatically

  2. Role authorized

    Compliance Officer

  3. Human sign-off

    Approved by J. Doe

  4. Logged to the audit trail

    Replayable, end to end

RecordingSOC 2 · ISO 27001

SOC 2 Type II · ISO 27001 · ISO 42001 · GDPR posture · Trust Center

SOC 2

Type II report, available under NDA

ISO 42001

Certified 2023, AI management system

Pen-tested

Independent report, on request

Trust Center

Live posture + sub-processors

Compliance by architecture

The strongest audit trail isn't written after the fact. It's the run itself.

Security isn't a layer you wrap around the agent. It's a property of the one environment the agent already runs in, so enforcement and evidence are the same system.

Data Protection

Where does the data live, and who can read it?

Encrypted at rest and isolated per project. Where the upstream provider supports a zero-retention path, your prompts and outputs are never kept on their side.

  • Encryption at rest
  • Project isolation
  • ZDR where supported

Identity & Access

Who is allowed to change the system?

Your team signs in with the identity provider it already uses. Roles decide who can ship, and the Copilot pauses every change for a named human before it reaches production.

  • Google / GitHub SSO
  • RBAC
  • Approval gates
  • Key rotation

Supply Chain

Whose hands touch your data on the way through?

Every provider in the path is named and listed for your procurement team, and you can see exactly which one handled any given run.

  • Transparent routing
  • Public sub-processor list
  • Pen-tested

Data Sovereignty

Who owns the record, and can you take it with you?

Your trace and your data stay yours: transparent routing, no upstream retention where supported, and exportable, so there is no lock-in to defend to your board.

  • Transparent supply chain
  • Trace ownership
  • Data export

Trust Center

The documents your security team asks for.

SOC 2 Type II, ISO 27001 and ISO 42001 evidence under NDA, an independent penetration test, and a public sub-processor list. The posture, available before procurement asks.

  • SOC 2 Type II report

    Available under NDA

  • ISO 27001 + 42001 certificates

    Available under NDA

  • GDPR posture + DPA

    Documented; DPA on request

  • Sub-processor list

    Public on the Trust Center

Trust & Security

Procurement-ready. CISO-approved.

SOC 2 Type II, ISO 27001 and ISO 42001 evidence under NDA, GDPR posture documented, sub-processor list public. Get the answers your security team needs before the contract is signed.