Trust Center

Trust, stated exactly.

For enterprise buyers, trust is evaluated before capability. This page states our security and AI-governance posture precisely — current statuses, real controls, and nothing claimed before it is earned.

Current status

SOC 2 examination underway — controls implemented and operating.

We additionally completed the customer security review required for a production deployment in an aerospace & defense environment. We publish exact statuses here and display accreditations only from the day they are real — never a day before.

Controls

What is implemented and operating.

Encryption

AES-256 at rest, TLS in transit, credentials encrypted and held in a managed secrets store. Your data stays in your environment.

Identity & access

SSO integration, role-based access control, least-privilege by default.

Approval architecture

Human approval gates on every write-back. Segregation of duties preserved.

Audit trail

End-to-end logging: signal, recommendation, evidence, approver, action, result.

Evaluations before production

Every critical workflow is tested against customer-approved cases before go-live; exceptions and human corrections are tracked in production.

Kill switch

Every deployed workflow and agent run can be halted instantly — and nothing writes back without a named human approval.

Model & prompt versioning

Versioned, reviewable, reproducible — the model state behind any decision can be reconstructed.

Data isolation

No data shared across clients. Client-controlled model endpoints with zero-data-retention posture toward providers; customer data is not used to train shared models.

Deployment architecture

Where your data lives, exactly.

Your tenant · your VPC · your keys
ERP
SAP · Costpoint · NetSuite
untouched, clean-core
MANTRIX RUNTIME
Nexus graph · modules · audit streams
side-by-side deployment
AUDIT LOG
Every signal → action
immutable, exportable
AES-256 at restTLS in transitSSO / RBACnamed approvers

The only thing that crosses the boundary: governed prompts to client-controlled model endpoints — zero-data-retention posture, customer data never used to train shared models. No cross-client data, ever.

Model endpoints

Client-controlled · ZDR · your choice of provider or self-hosted

Your approvers

Humans approve every write-back — segregation of duties preserved

Kill switch

Halt any workflow instantly; roll back any action

AI governance

Organized around NIST AI RMF.

Our deployment methodology maps to Govern, Map, Measure, Manage — the language A&D and GovCon buyers already use.

Govern

Named accountability, approval architecture, segregation of duties, and policy for every deployed workflow.

Map

Each use case mapped to its data, its systems, its failure modes, and the people affected — before build.

Measure

Test suites built from customer-approved cases before go-live; exceptions and outcomes tracked in production.

Manage

Monitoring, incident response, kill switch, and periodic review — production is a lifecycle, not a launch.

Accreditation roadmap

Exact statuses. No early badges.

SOC 2 (Type I → Type II)Examination underway — controls implemented and operating
SAP PartnerEdgeIn progress
Deltek MarketplaceIn progress
Oracle NetSuite SuiteCloudIn progress
ISO 27001Planned — sequenced after SOC 2
ISO 42001 (AI management)Planned — sequenced after SOC 2 Type I

Known limitations, deployment options, subprocessors, and our standard security questionnaire are available on request while this page is built out — contact us.