Beta waitlist — not a public launch, and no live checkout. Request early access
Trust & controls

We claim only what we can show.

Most AI products describe their safety. We'd rather show you the control board — what's certified, what's enforced today, and what's still being built. Every control runs on our own operations before a customer ever touches it.

★

Service-Disabled Veteran-Owned Small Business

Certification complete. Vetworx Solutions is SDVOSB-certified. Named control profiles come later.

✓ Complete
ControlStatusWhat it means in practice
Human approval gates ◐ In progress Privileged agent actions — credentials, spend, production and DNS changes — pause for an explicit human "approved, go." Enforced on our own infrastructure today: this very website's DNS changes each waited for a named person's approval.
Least-privilege credentials ◐ In progress Agents hold narrowly scoped, deny-guarded credentials — a DNS token that can touch only the zones it manages, cloud roles with permanent deny rails verified against the live policy, then narrowed further from real usage data.
Append-only audit trail ◐ In progress Replica retention no longer sweeps audit logs. The approval-record schema — who approved what, when, under which policy — is the next seam, designed before the platform opens to customers.
Tenant isolation ✓ Complete Every customer's data, agents, and tasks scoped hard to their tenant. Login and API routes bind to the Host header; a token from one tenant cannot read another.
Per-customer compliance profiles ○ Planned The control set flexes by configuration: a full set, or a solo site owner's minimal one. Same platform, your profile.

Your identity, your call

Guardrails only mean something if they're anchored to an identity system you trust.

Bring your own

Active Directory / Entra

Verify approvals and permissions against your existing directory. Your users, your groups, your conditional access — we integrate, not replace.

Bring your own

AWS infrastructure

Anchor the permission envelope in your own IAM — roles you define, deny rails you can read, credentials that never leave your account's control.

Fully managed

We run the envelope

No directory? No problem. We can operate the guardrails and permission sets for the tasks being done — MSP-grade, documented, auditable. Public checkout is not open.

Why the board looks like this

An honest "in progress" beats a decorative "certified." Buyers who've been burned know the difference.

We run ourselves as tenant zero. The gates, credentials, and audit design on this board already govern the agents that operate our infrastructure.

By the time a control reaches a customer, it has been used in production — not written for a brochure. When a planned control lands, its row moves, and the evidence moves with it.

Ask us the hard questions.

Compliance requirements, identity constraints, an auditor with opinions — bring them. That conversation is the product working as intended.

Request early access Or email us