Security & Compliance

Security and compliance for AI agents

Praesidia is built security-first: every agent gets its own identity, every interaction is inspected and logged, and every record is tamper-evident. The controls and evidence map directly to the frameworks your auditors care about.

Controls

Security built into every layer

Not bolted on after the fact — the platform is the security.

Non-human identity for every agent

Every agent authenticates with its own credential — attributable and individually revocable, with no shared service accounts. New agents get JIT ephemeral credentials by default, secrets rotate with zero downtime, and single-agent revocation contains the blast radius to one agent when it is compromised.

Tamper-evident audit trail

Every request, response, and policy decision is recorded in a cryptographically verifiable log that holds up in an investigation — and you can check it yourself, offline, without trusting our servers. See how →

Tenant isolation

Strict multi-tenant isolation so one organization can never read another's data — every request is scoped to your organization, with database row-level security on the most sensitive tables.

SSO & SCIM for the humans

For the people who manage your agents: SAML and OIDC single sign-on, automated user lifecycle with SCIM, MFA, and passkeys.

Least-privilege access

Role-based access control and scoped API keys, so every human and integration gets exactly the access it needs and no more.

Content guardrails

Bidirectional inspection blocks prompt injection and stops sensitive data from leaving through an agent's output.

Signed, verified webhooks

Outbound events are signed so your systems can verify they genuinely came from Praesidia before acting on them.

Vaulted secrets with per-region BYOK

Provider keys and agent credentials are vaulted on a Vault Transit substrate — shown once, never exposed in logs or read back in plaintext. Regulated deployments encrypt under per-region bring-your-own-key (BYOK) KMS, so residency and key custody hold at the storage layer.

Independent Verification

Don't take our word for it — verify it yourself

Every compliance bundle you export can be checked by your own team or your auditor with @praesidia/audit-verifier — an Apache-2.0, dependency-free CLI that runs fully offline and never calls our servers. It confirms every signature, the full hash chain, every tamper check, and — when enabled — the independent Sigstore Rekor transparency-log anchor, a log we don't control. It also states plainly what it does not prove, on purpose.

See the command and the full trust model →

Data Residency

European infrastructure, by choice

Security starts with where your data lives and who processes it. Praesidia runs on European infrastructure and works with European technology providers so your data stays within the EU and under the strictest data-protection regulations. For the full story, see about Praesidia and data residency for AI agents.

Responsible Disclosure

Found a vulnerability? Tell us

We welcome reports from the security community and practice coordinated disclosure. Our Vulnerability Disclosure Policy covers scope, safe-harbor, and how to report; machine-readable contact details are at /.well-known/security.txt. We also test ourselves — see continuous adversarial testing for AI agents.

Govern AI with confidence

Get started for free. No credit card required.