Aigentical sits in the path of your AI agents' actions, so we hold it to the standard that placement demands: single-tenant, your keys, a record you (not we) control, and nothing that leaves your boundary unless you send it there.
Last updated: July 2026 · security@aigentical.ai
Governance decisions and their metadata — the acting identity, the action, the verdict (allow / hold / deny), the reason, and a timestamp — written to a tamper-evident audit chain.
The audit chain is HMAC-linked and keyed in your own KMS or HashiCorp Vault (bring-your-own key). Because the signing key is yours, the record can't be silently rewritten — including by us — and any tampering is caught on the next verify-on-read.
Integrity keys and secrets are never bundled with the application or checked into source.
Our controls are mapped to the frameworks your program already answers to:
Framework mappings are Aigentical's own and are provided to accelerate your program; they do not imply certification or endorsement by the framework owners.
Found something? Email security@aigentical.ai. We'll acknowledge quickly and work the fix with you; we don't pursue good-faith researchers.