هذه الصفحة غير متوفرة بالعربية بعد — تُعرض بالإنجليزية.
Trust Center
Accountability, built in.
Intelligence is becoming abundant. Accountability isn't.
95% is the layer designed to make AI accountable — every action permissioned, isolated, and recorded in a log you can export for audit. Here is how it's built and where we're headed.
Security is the foundation, not a feature.
Three layers of the operating system are designed to carry trust.
Trust · Secure Runtime
Isolated execution + tamper-evident audit
Agent actions are designed to run in an isolated sandbox under least privilege and be recorded in an append-only, tamper-evident audit log you can export and verify.
Intelligence · Smart Router
Redaction + prompt-injection filtering
Sensitive-data redaction and prompt-injection filtering are designed to run around model calls. Model-agnostic by design, with support for zero-retention provider configurations.
Workforce · AgentOS
Identity, permissions, and approval gates
Each AI worker has a scoped identity with per-tool permissions, role-based access, and human approval gates on high-risk actions — granted, revocable, and logged.
Your data stays yours.
Ownership and privacy by design.
You own your data
Your data powers your agents. Single-tenant isolation by design — not shared across customers.
Zero-retention support
The architecture supports zero-retention provider configurations, so prompts and outputs aren't retained for training.
Encryption
Data is encrypted in transit and at rest.
Deletion & retention
Designed to support data deletion and configurable retention windows.
Deploy on your terms.
Available today, with more deployment options on the roadmap.
Managed cloud
Run on our managed cloud with per-customer isolation.
Your cloud — roadmap
Deploying into your own cloud account is on our roadmap.
Self-hosted — roadmap
Self-hosted and air-gapped deployment are on our roadmap.
Bring your own models & keys
Model-agnostic by design — run on your own provider accounts and keys.
Enterprise access & identity.
Available today or on our roadmap — confirm scope with our team.
Compliance roadmap.
Where we are and where we're going — stated honestly.
These reflect our design posture and roadmap, not active certifications. Current status is available on request.
Operated with discipline.
Security is continuous, not a checkbox.
Monitoring
The architecture supports runtime monitoring of agent behavior with anomaly detection.
Incident response — roadmap
We're formalizing a documented incident-response and customer-notification process.
Responsible disclosure
Report a security concern through our contact form; we operate a coordinated-disclosure process.
Sub-processors
A current sub-processor list is available on request.
What your security review needs.
Request our current documentation; we'll share what's available under NDA.
- Security & architecture overview — on request
- SOC 2 report — when available, under NDA
- Data Processing Agreement (DPA) — on request
- Sub-processor list — on request
- Current compliance status — on request
Questions security teams ask
- Can AI agent actions be audited?
- Yes. Every agent action on the 95% platform is recorded in an append-only, tamper-evident audit log that can be exported and verified — each execution sealed as a signed, HMAC-chained receipt that can be replayed.
- Who is responsible when an AI agent acts?
- Every action has an owner. Anything without an owner is surfaced by the platform, and anything that shouldn't have run can be reversed. Responsibility is engineered into execution, not implied by policy.
- What does a security review need to approve AI agents?
- Per-tool permissions and role-based access, human approval gates on high-risk actions, per-team budgets and model allow-lists, and an exportable tamper-evident audit record. Our security overview, DPA, and sub-processor list are available on request.