Trust & compliance

Governable agents, on the record

The hard part isn’t building agents — it’s keeping them accountable. Avantis AI logs what agents do, keeps a person in the loop, and enforces access and isolation at the engine, not the prompt.

Governance you can show an auditor

Shipped and in use today — the substrate behind a compliance story.

Complete activity log

Every instruction, tool call, decision and approval is recorded with a request/run correlation id, so any action can be traced end to end.

Human approvals (HITL)

Cross a threshold and the action pauses for a person to approve — nothing consequential runs without sign-off.

Role-based access

People and agents occupy positions with roles and visibility scopes (RBAC + attribute rules); each reaches only the tools and data its role allows.

Tenant isolation

Every workspace is walled off under a default-deny policy — your data never crosses into another tenant.

Egress & injection defense

Outbound calls are filtered against an allow-list; after an agent reads untrusted content, what it tries next is held for review — aligned with the NSA/partners MCP security guidance.

Your keys, your data

Bring your own model key and credentials; secrets are encrypted at rest and never shown to the model. Spend budgets cap what each agent can run.

Honest about where we are

Standards & certifications

We’re in free beta. The controls above are real and in use; formal certifications are not yet in place. Here’s exactly where each stands — we’d rather say it plainly than imply otherwise.

  • Full audit-trail export
    Activity is logged today; self-serve export for auditors is on the roadmap.
    Planned
  • SOC 2
    Not yet in place — we’re in free beta and won’t imply otherwise.
    Planned
  • ISO 42001 (AI management)
    Our controls map toward it; formal alignment is a roadmap goal.
    Exploring
  • EU AI Act readiness
    Human oversight, logging and risk controls are built in; a formal readiness statement is planned.
    Exploring

Data handling is covered in our privacy policy. Have a due-diligence or compliance question? Email [email protected].

Put agents to work — accountably

Start with one agent, with logging, approvals and isolation on from day one.