Security
Security and compliance
Agents touch production systems and customer data, so the boring controls matter more than the demo. Here is what we hold, what we log, and where your data lives.
SOC 2 Type II
Audited annually by an independent firm. Full report available under NDA.
GDPR
EU data processing agreement, DPIA support, and EU-only residency on request.
HIPAA
BAA available on Enterprise. PHI is excluded from trace payloads by default.
ISO 27001
Certified information security management system, reviewed each year.
How we operate
Encryption
TLS 1.3 in transit and AES-256 at rest. Trace payloads are encrypted with per-workspace keys.
Access control
SSO via SAML or OIDC, SCIM provisioning, and role-based access down to the individual agent.
Data residency
Choose US or EU storage, or run the control plane entirely inside your own VPC.
Audit logging
Every configuration change, key issue, and trace export is logged and retained for one year.
Penetration testing
Third-party tests twice a year, plus continuous automated scanning against every release.
Incident response
On-call rotation with a one-hour acknowledgement target and public post-incident write-ups.
FAQ
Questions engineers actually ask
The things teams want settled before they put an agent in front of a customer.
Still deciding?
Read the quickstart and get a live trace out of your own agent in about ten minutes.