Trust center

How identity, permissions, models, tools, and evidence fit together.

Review the identity, permission, data, model, tool, and evidence boundaries that must be resolved before production access.

Control plane

Five boundaries every agent must cross correctly.

Governance follows the request from identity to retrieval to reasoning to action. Every boundary can apply policy, stop execution, request review, and preserve evidence.

Identity

One user, one permission boundary.

Map SSO identity, groups, roles, source ACLs, and service principals before retrieval or action.

Data

Minimize context before models see it.

Classify, mask, exclude, regionalize, and retain enterprise data according to purpose and policy.

Models

Route intelligence through approved paths.

Set task-level model policies, prompt controls, fallback routes, cost limits, and restricted-use rules.

Actions

Treat writes as controlled business events.

Use tool allowlists, field scopes, confidence thresholds, human approvals, and bounded credentials.

Evidence

Reconstruct every important decision.

Retain the request, identity, context, citations, model route, policy result, approvals, and action outcome.

Assurance status

Separate current evidence from product intent.

S/Runtime is presented here as an enterprise architecture and design-partner platform. This public site does not claim independent certification, authorization, or production suitability for a regulated environment.

Available

Public product preview

Architecture, control model, solution patterns, and an illustrative product simulation.

Engagement-specific

Pilot security package

Data flow, source and model boundaries, control ownership, retention, incident paths, and evaluation scope.

Confirm in discovery

Capability availability

Generally available, configurable, pilot, and planned capabilities must be recorded in the engagement scope.

Not claimed

Independent assurance

No certification, ATO, compliance attestation, or third-party assessment is represented by this website.

Agent threat model

Design for hostile context and irreversible work.

Agent security extends beyond model safety. These are design requirements to validate in a pilot threat model, not blanket guarantees that every deployment has already implemented them.

Prompt and instruction attacks

Treat retrieved content and tool output as untrusted; separate system policy from content and evaluate suspicious instruction patterns.

Poisoned or stale context

Track source authority, freshness, ownership, conflicting evidence, and retrieval coverage before context is accepted.

Memory misuse

Authorize memory writes separately from reads; scope personal, team, and enterprise memory with retention and deletion rules.

Credential and tool abuse

Keep credentials outside model context, delegate narrow scopes, validate parameters, and re-authorize consequential actions at execution time.

Unsafe egress and side effects

Restrict destinations, network paths, objects, fields, rates, and action sequences; use idempotency and compensating workflows where possible.

Loss of operator control

Provide pause, revoke, disable, escalation, and incident paths with accountable owners and preserved evidence.

Request-to-action evidence

See the complete path, not just the final answer.

Identity
Source ACL
Context pack
Model route
Policy check
Approval
Action log

Data and model boundary

Document what crosses each boundary before a pilot connects.

These are required design decisions for an engagement. Provider, region, retention, deletion, support-access, and model-training terms are not implied by the public preview.

Source handling

Define what is indexed, embedded, cached, streamed at query time, or left only in the source.

Model routing

Record approved providers, prompt contents, regional routes, retention terms, and restricted-use policy.

Lifecycle

Set retention by artifact, deletion propagation, backup handling, legal holds, and evidence minimization.

Administrative access

Limit and record support access, privileged operations, emergency paths, and customer revocation.

Incident and continuity

Name reporting contacts, severity paths, recovery ownership, evidence preservation, RTO, and RPO targets.

Assurance

Attach dates, scope, exceptions, owners, and expiration to every assessment or control artifact.

Request a pilot security package

Control alignment

Map platform evidence to the programs your enterprise runs.

These are control-mapping and evidence workflows, not claims of certification. Final applicability and assurance depend on your deployment, contracts, processes, and audit scope.

SOC 2 and ISO 27001 programsAccess control, change management, operations, incident response, supplier risk, and evidence collectionMapping scope
GDPR and CCPA/CPRAPurpose limits, minimization, data mapping, regional controls, retention, and request workflowsMapping scope
HIPAA and HITECHMinimum-necessary context, PHI-aware retrieval, access logs, review gates, and business-associate boundariesMapping scope
GLBA and financial controlsCustomer-data safeguards, segregation of duties, privileged actions, retention, and supervisory evidenceMapping scope
NIST AI RMF and ISO 42001AI inventory, risk classification, measurement, oversight, monitoring, and continuous improvementMapping scope
FedRAMP, CMMC, and NIST 800-171Boundary definition, identity, CUI-aware handling, control evidence, and deployment reviewMapping scope

Applicability, control ownership, evidence sufficiency, and audit conclusions remain the responsibility of the customer and its qualified assessors. Read the public-site privacy boundary.

Architecture session

Bring one consequential workflow. Leave with a governed agent blueprint.

We will map the context, systems, decisions, controls, actions, and success measures together.

Talk to an architect