Trust Center

Trust, stated exactly.

For enterprise buyers, trust is evaluated before capability. This page states our security and AI-governance posture precisely — current statuses, real controls, and nothing claimed before it is earned.

Current status

SOC 2 examination underway — controls implemented and operating.

We additionally completed the customer security review required for a production deployment in an aerospace & defense environment. We publish exact statuses here and display accreditations only from the day they are real — never a day before.

Controls

What is implemented and operating.

Encryption

AES-256-GCM in transit and at rest. Your data stays in your environment.

Identity & access

SSO integration, role-based access control, least-privilege by default.

Approval architecture

Human approval gates on every write-back. Segregation of duties preserved.

Audit trail

End-to-end logging: signal, recommendation, evidence, approver, action, result.

Evaluations before production

Every critical workflow is evaluated against customer-approved test cases before go-live; accuracy, exception rates, and human corrections are monitored continuously after.

Kill switch & rollback

Every deployed workflow can be halted instantly and every action rolled back.

Model & prompt versioning

Versioned, reviewable, reproducible — the model state behind any decision can be reconstructed.

Data isolation

No data shared across clients. Client-controlled model endpoints with zero-data-retention posture toward providers; customer data is not used to train shared models.

Deployment architecture

Where your data lives, exactly.

Your tenant · your VPC · your keys
ERP
SAP · Costpoint · NetSuite
untouched, clean-core
MANTRIX RUNTIME
Nexus graph · modules · evaluations
side-by-side deployment
AUDIT LOG
Every signal → action
immutable, exportable
AES-256-GCM at restTLS in transitSSO / RBACnamed approvers

The only thing that crosses the boundary: governed prompts to client-controlled model endpoints — zero-data-retention posture, customer data never used to train shared models. No cross-client data, ever.

Model endpoints

Client-controlled · ZDR · your choice of provider or self-hosted

Your approvers

Humans approve every write-back — segregation of duties preserved

Kill switch

Halt any workflow instantly; roll back any action

AI governance

Organized around NIST AI RMF.

Our deployment methodology maps to Govern, Map, Measure, Manage — the language A&D and GovCon buyers already use.

Govern

Named accountability, approval architecture, segregation of duties, and policy for every deployed workflow.

Map

Each use case mapped to its data, its systems, its failure modes, and the people affected — before build.

Measure

Evaluation suites with customer-approved test cases; accuracy, exceptions, and drift measured continuously.

Manage

Monitoring, incident response, kill switch, rollback, and periodic review — production is a lifecycle, not a launch.

Accreditation roadmap

Exact statuses. No early badges.

SOC 2 (Type I → Type II)Examination underway — controls implemented and operating
SAP PartnerEdgeIn progress
Deltek MarketplaceIn progress
Oracle NetSuite SuiteCloudIn progress
ISO 27001Planned — sequenced after SOC 2
ISO 42001 (AI management)Planned — sequenced after SOC 2 Type I

Known limitations, deployment options, subprocessors, and our standard security questionnaire are available on request while this page is built out — contact us.