Security Architecture

Your data never persists.

Micro-SCIF isolation. Sovereign compute. Forensic vaporization. Every engagement is sealed, executed, and destroyed — with cryptographic proof.

Zero retention AES-256 encryption Kill-switch available

Ephemeral Access Tokens

KMS-scoped tokens with automatic expiry. No passwords stored. No persistent credentials. Access auto-revokes on expiration — all associated encrypted data becomes permanently unreadable.

  • Time-bounded grants (configurable TTL)
  • KMS encryption — token is the key
  • Auto-revocation on expiry
  • Identity verification required for refresh

Micro-SCIF Chambers

Every diagnostic and execution runs inside an isolated chamber. No cross-contamination between sessions, no shared state, no lateral movement possible.

  • Sealed inference — diagnostics contained
  • Sealed execution — fixes run in isolation
  • Sealed storage — temporary only, then wiped
  • No cross-session contamination
  • Each engagement is its own security boundary

Zero External Network Calls

All intelligence runs on sovereign AWS Bedrock compute within our VPC. Zero calls to external LLM APIs. Zero data exfiltration vectors. Your information never leaves our controlled infrastructure.

  • AWS Bedrock (sovereign compute)
  • VPC-isolated inference
  • No OpenAI / external AI calls
  • No telemetry to third parties

Forensic Vaporization

Upon engagement closure, all operational data undergoes a 17-table relational purge. You receive a SHA-256 destruction certificate proving complete elimination.

  • 17-table relational purge
  • Storage wipe (all temp artifacts)
  • SHA-256 destruction certificate issued
  • Zero retained logs or history
  • Cryptographic proof of destruction

Kill-Switch Protocol

Instant termination available at any point. One click from your portal destroys all active sessions and temporary data immediately. No waiting period, no approval chain.

  • Instant session termination
  • Immediate data destruction
  • Client-triggered (no operator required)
  • Destruction certificate issued automatically

Human-in-the-Loop Governance

No automated system touches your infrastructure without human approval. Every fix requires explicit sign-off before execution. You see exactly what will change before it happens.

  • Quote approval required before work
  • Fix preview before execution
  • Real-time progress visibility
  • Rollback capability on all changes

How We Access Your Systems

Multiple access models — you choose the level of trust. We never require permanent credentials.

OAuth / Temporary Tokens

Lowest risk

Time-bounded API tokens that auto-expire. No stored credentials.

Temporary SSH Keys

Low risk

Generated per-engagement, destroyed on completion. Never reused.

JSON Config Upload

Minimal risk

You export config, we import it. No live access to your systems.

Screen Share / Guided

Zero risk

You maintain control. We guide, you execute. Zero access granted.

Identity Retained, Data Vaporized

What we keep

  • Your name and email (for support)
  • Ticket history (status only, not content)
  • Payment records (Stripe-managed)

What we destroy

  • All diagnostic data
  • All uploaded files and configs
  • All execution logs and session data
  • All temporary credentials

Compliance & Certifications

Zero-retention architecture exceeds most compliance frameworks by default.

SOC 2 Type II

In Progress

Audit scheduled. Architecture already exceeds TSC requirements.

GDPR

Compliant

Zero-retention architecture. Right to erasure built-in by default.

CCPA

Compliant

No personal data sale. Destruction certificates on request.

PIPEDA

Compliant

Canadian privacy law compliance. Data sovereignty maintained.

Questions about our security posture?

We provide custom security briefs and can arrange calls with our infrastructure team for enterprise evaluations.