[ Security ]

Governance is the security model.

Every agent action is evaluated, scoped, and logged. Security isn’t a layer on top of Hexel — it’s the runtime itself.

[ Practices ]

Encryption

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256) across every plane.

Isolation

The Dedicated plane offers per-tenant isolation, with optional VPC and data residency.

Access control

Scoped service identities, SSO, and advanced RBAC for every fleet and resource.

Audit

Immutable logs of every governed decision, streamable to your SIEM in real time.

Secrets

Credentials and keys are stored in an isolated vault and never exposed to agents.

Monitoring

Continuous monitoring and anomaly detection on the control and execution planes.

[ Compliance ]
SOC 2 Type IIGDPRISO 27001*HIPAA-ready*

* in progress

Questions about our security posture?

Start building