Security & trust

What actually protects your data here.

The isolation, audit, and sensitive-data handling a regulated product needs are native to the platform, not a layer you bolt on after your first security review. Here’s exactly what holds, and where the boundary is.

The posture

The same posture, on every tier.

Tenant isolation is enforced structurally at the data layer. Credentials are validated at the edge before any application code runs. Every public surface terminates TLS and every storage surface is encrypted at rest. The data-plane inference path runs inside the Vectros perimeter, the same posture on every tier.

Sensitive-data handling

Three separate mechanisms protect a sensitive field.

They operate at different points in the data lifecycle. Redact-at-write protects history; read-time masking protects live reads; search-exclusion protects retrieval. Three independent guarantees, not one restated.

01

Redact-at-write

destroyed before persist

A sensitive field’s value is redacted out of the retained version history and the structured change-diff before anything lands in durable history. This is not reversible masking; it’s destruction. No scope, credential, or later request can recover it, because it was never written there.

02

Read-time masking

hidden unless the token reveals it

A token without the explicit reveal scope sees the field obscured. A token deliberately granted reveal authority sees the cleartext. This is the runtime access control on sensitive data still present in live rows.

03

Search-exclusion

never enters the index

Sensitive fields are excluded from the search index at index time: never embedded, never tokenized. No query, semantic or keyword, can surface a sensitive value or use it as a matching signal, because it isn’t in the index to match against.

The trust story

Properties, not adjectives.

A version history built to survive an auditor, isolation that denies access by default as a platform property, surfaces hardened by adversarial review, and an agent caller held to the identical boundary a person is.

01

Tamper-evident version history

Every write to an audited model accrues a tamper-evident version record, built to survive an auditor.

  • What changed, who changed it, and the prior content, with sensitive fields already redacted.
  • Deletions leave a tombstone.
  • Tamper-evident: a SHA-256 state-continuity chain makes out-of-band alteration detectable.
  • Heavy history moves to a write-once, retention-locked store (default ~7-year horizon), dispositioned only through a policy-aware path, never silent auto-expiry.
02

Isolation as the guarantee

Every application context is a mandatory partition derived from the credential, never a wildcard: a lookup that can’t prove it belongs there returns nothing, not everything.

  • Probing with someone else’s id returns the same “not found” as an invented one. Errors aren’t a discovery channel.
  • Hybrid search inherits the same boundary.
  • Filter inputs are allow-list validated, so a crafted filter can’t break out of the tenant clause.
  • Isolation is a platform property, not a row-level rule that one forgotten WHERE clause could break.
03

Hardened by adversarial review

Partner-facing surfaces have been hardened through extensive adversarial security review.

  • The review exercised tenant isolation, scope enforcement, key construction, the edge, the authorizer, and the webhook machinery.
  • Do-not-regress constraints from that work are enforced mechanically in the codebase, so the fixes can’t silently erode.
04

Agent access is the same policy, not a new review

An AI agent reading your data is just another caller against the identical declarative policy that already enforces isolation for every person.

  • A scoped key and the published MCP server both mint from the same access-profile mechanism as a human role, not a separate one.
  • Narrowing an agent to one record type in one compartment is a role definition in the blueprint, not new authorization code to write and review.
  • The isolation boundary above holds for an agent caller exactly as it holds for a person, because the enforcement layer doesn’t distinguish between them.
  • Twenty-three data-plane MCP tools ship today. No web-fetch or external search, by design. See the tools page.

Tamper-evident, not tamper-proof. The chain makes alteration detectable; it does not make the store physically immutable.

What this guarantee stops at.

Where the boundary is

What’s covered, and what isn’t.

Evaluate these explicitly for a regulated workload.

Audit history is tamper-evident, not tamper-proof.

The chain makes out-of-band alteration detectable; continuous automated verification isn’t part of the shipped surface.

In-perimeter inference is scoped to the data plane.

It’s not a whole-platform legal representation. The platform gives you a HIPAA-grade substrate; it doesn’t make your own application HIPAA-grade on its own.

You can fully delete a tenant’s data.

Decommissioning a tenant runs a real, irreversible cascade, not a soft-delete flag.

Reviewed, not certified.

We don’t hold a SOC 2 report or a third-party penetration test today. Both are on the roadmap, and we don’t represent otherwise.

Some controls aren’t built yet.

Retention duration is a platform constant, not a customer-configurable setting, today. Ask under NDA where it stands.

The agent/MCP surface has no web tools.

No web-search or web-fetch: nothing auto-scrapes, by design. File uploads through the agent work over the primary stdio transport; the hosted HTTP transport is text-inline only. Bootstrap still needs a real developer-portal sign-in, not a fully unattended flow.

See it

The version history, made visible.

The Audit History view renders the version timeline of a record: who changed what, when, with sensitive fields redacted in every historical row.

Audit Historyrecord rec_8f3a · intake_case
VerActorChange
v4svc.intake-botstatus: in_review → triaged
v3dr.okaforrisk_note: ••••••••• (redacted)
v2svc.intake-botpriority: normal → elevated
v1dr.okaforrecord created · 7 fields
Illustrative, synthetic data. Sensitive fields are destroyed before they reach retained history.

Proof points

Things you can actually run.

Pick a blueprint and provision it in one command, or fork a full reference app and point it at your own identity provider. Zero application code either way.

The RAVV reference app

reference app

A full customer-facing app with its own sign-in and zero backend of its own. An architectural proof, not a policy one: fork it, and the isolation and audit above hold without a line of authorization code you wrote yourself.

Clinical Intake

blueprint

Structured intake that validates on the way in and surfaces the most similar prior cases by meaning. Compliance-first, on healthcare home turf. Decision support, not decisioning.

Audit History view

visual hero

The version timeline made visible: who changed what, when, with sensitive fields redacted in every historical row.

Agentic-SDLC Knowledge Base

blueprint

A coding agent that remembers decisions, conventions, and gotchas across sessions, isolated per principal, with no application code.

Second Brain

blueprint

Dump every note, idea, and link in one place, then just ask it: the widest, lowest-stakes on-ramp.

Compliance specifics are available under NDA

HIPAA terms, Business Associate Agreement coverage, attestation status, and the exact scope of the in-perimeter inference path.