Company / Trust

What a security review gets, in writing.

The questions a security review asks first, answered on a page rather than in a questionnaire round-trip. Where a control is configuration-dependent or not yet measured, it says so.

Fail-closed by contract No model can permit an action Deployable in your environment

SECURITY PRINCIPLES

Three properties the architecture holds.

These are structural, not configurable. They are the reason the rest of this page can be read at face value.

Zero-trust by default

No agent holds implicit access to any system. Every action is evaluated against policy before it reaches a system of record.

enforced
Fail-closed

Any transport error, timeout, non-2xx or unparseable response resolves to deny, never to allow. Enforcement does not degrade quietly.

by contract
A model can only ever add a deny

The policy engine is deterministic — YAML and OPA/Rego — and the verdict it produces is the strictest outcome across every detector. An optional model-backed detector can contribute a deny. Nothing a model returns can turn a deny into an allow, and if it is unavailable it fails closed rather than degrading to one. Models draft policy and study decisions after the fact; none of them decides that a consequential action may proceed.

enforced

DEFAULT POSTURE

What is on the moment you install it — and what is not.

Every buyer asks this, usually after signing. It belongs on the page instead. Three states, and the difference between them is deliberate: nothing that touches your systems turns itself on, and nothing that records what happened waits for permission.

Live with no governance configuration

The record, and the decision path

  • A hash-chained, tamper-evident audit ledger: the database itself rejects an edit to an entry already written, and the chain makes a removal visible. Tamper-evident is the accurate word — the guarantee is that interference shows, not that it is impossible.
  • A real-time decision path that evaluates every governed call.
  • Seven built-in payload detectors on every governed call. Six classify out of the box — among them credential and secret material, structurally validated payment-card and US Social Security numbers, and a known-phrase prompt-injection check. The seventh is your own data-loss vocabulary, and it stays silent until you write those rules, because we will not guess what your organisation considers sensitive.
  • An action no policy covers is denied. The no-match default is fail-closed, not permissive.
  • A gateway configured for multi-tenant operation refuses to start rather than quietly fall back to process-wide configuration — an opt-out, not a default-allow.
  • Single sign-on enforcement fails closed: if the check cannot be read, access is refused rather than waved through.
Configured by you

Anything that touches your systems

  • Discovery connectors see nothing until you supply read-only credentials.
  • Each enforcement point carries traffic only once that integration is deployed in your environment.
  • Your business rules are written by you. We ship the engine, not your policy.
Off until enabled by name

Deliberately opt-in

  • Cryptographic evidence signing.
  • Separation-of-duties enforcement on approvals.
  • Agent auto-registration.
  • Provider-native guardrail push-down.
  • Outbound shadow-AI polling.
The asymmetry worth naming What you configure is what reaches it. Once a call does reach it, an unconfigured deployment still acts.

This is the opposite of the usual shape, and it is deliberate. A governed call arriving at a gateway nobody has tuned is not waved through pending setup: a credential in the payload is redacted, sensitive values are masked, and an action no policy covers is denied. Turning GovernorAI on is a decision about which traffic it sees — never a decision about whether it is paying attention.

DATA HANDLING

What is logged, and what is not.

The distinction that determines whether governance logs are themselves a data-protection problem.

What is logged

Structured governance events: agent ID, session ID, tool name, policy decision, timestamp, latency. Designed to be read by an auditor.

enforced
What is not logged

No raw prompts. No model outputs. No customer PII in governance logs. GovernorAI records the decision, not the conversation.

enforced
Data residency

Self-hosted deployments keep all data inside your environment. Hosted deployments support region selection.

per deployment
Encryption

AES-256-GCM for credentials at rest, with a production guard that refuses to start without a persistent key. TLS 1.2 or higher in transit. Mutual TLS is available as a configuration option for the external policy-engine connection — not a blanket property of internal traffic.

aes-256-gcm · tls 1.2 floor
Tenant isolation

Row-level isolation with per-tenant scoping, verified by an isolation inspector rather than asserted.

enforced
Retention

Governance events are retained in the evidence ledger for the period the plan enforces — 7 days on Free, 30 on Startup, 90 on Pro, 180 on Team. The cap is a plan entitlement rather than a deployment setting.

DEPLOYMENT

Your security requirements decide the shape.

Hosted

Managed GovernorAI infrastructure. We operate, scale and update it; you configure policy and govern your agents.

per deployment
Self-hosted

GovernorAI runs entirely in your infrastructure. No governance data leaves your environment.

per deployment
Air-gapped

An architectural shape for sites that cannot reach a control plane at all. Available by enterprise qualification, not as a standard tier.

per deployment
You keep the keys

The SDK is a thin client. You keep every credential, all tool code and all control flow. GovernorAI is not a proxy in front of your model provider.

no token path

ACCESS & IDENTITY

Who can change a policy, and how that is proved.

Access control

Role-based access control, SSO and SCIM provisioning, with separation of duties on policy approval.

rbac · sso · scim
Authentication

OAuth2/OIDC against your existing identity provider. No shared secrets.

enforced
Signed evidence

Ed25519/Merkle signed evidence bundles are available per deployment, and are not default-on. Configuration and verification are explicit.

configure

INCIDENT RESPONSE

Reporting a security issue.

Report to security@sentinellayer.dev.

Process

  • Acknowledgement of a reported security issue
  • Initial assessment and triage
  • Coordinated disclosure for confirmed vulnerabilities
  • Post-incident reporting to affected customers

We acknowledge a reported security issue within 24 hours, and complete initial assessment and triage within 72 hours. Both are measured from receipt at security@sentinellayer.dev. Coordinated disclosure timing for a confirmed vulnerability is agreed with the reporter, since it depends on the fix.

Safe harbour

We authorise good-faith security testing against GovernorAI-owned systems and designated staging environments, where testing avoids service degradation, data access beyond the tester’s own account, social engineering, denial-of-service, physical attacks, spam, and testing of third-party systems.

Stop and report promptly on encountering personal data, credentials or customer data. We will not pursue legal action for authorised good-faith testing that follows this policy. Reports go to security@sentinellayer.dev.

COMPLIANCE POSTURE

Controls that map, not certifications we hold.

GovernorAI produces controls and evidence that map to SOC 2 Trust Services Criteria, GDPR, HIPAA safeguards and EU AI Act obligations for high-risk systems. Mapping evidence to a control is not the same as holding a certification against it.

Intellectual property

Two U.S. provisional applications are on file.

Continue