Trust · Security overview
Security runs through the architecture. Agents inherit your permissions, act only where authorized, and leave a record of everything.
The controls, as a datasheet
Identity & access
- Inherited access model
- Agents see exactly what the person they work for may see.
- Checked at query time
- Access is evaluated per retrieval, never cached into the answer.
- Least privilege
- Write access scoped per workflow and granted explicitly.
Data protection
- Encrypted throughout
- In transit and at rest, on every deployment shape.
- Masking before models
- Sensitive fields are redacted before inference, per data class.
- Residency by design
- Data and inference run in the jurisdiction you designate; routing respects residency before fit or cost.
Governance
- Immutable audit log
- What ran, under whose authority, on which evidence, with what result. Exportable to your SIEM.
- Human boundaries
- You define what AI does alone and what waits for approval. Missions pause at those lines.
- Spend within limits
- Budgets per workflow, team and department; runaway loops stop at the boundary.
Where it runs
Your data stays where you choose.
- Cloud, in your jurisdiction
- Managed deployment on infrastructure in the region you designate.
- Regulation-ready
- Residency, masking and retention designed to meet GDPR, PDPL and sector rules.
- Sovereign & air-gapped
- Fully isolated deployment on request for regulated and government environments.
Security is enforced by the layer.
Permissions, masking and audit run inside Edrak Foundry's governance plane.
Explore Governance & audit →