Security and Compliance
Built to survive an audit
Automation that touches finance, identity and customer records has to answer to somebody. This page sets out how Automentic secures the platform, and how the evidence it produces maps to the frameworks your auditors work from.
Frameworks
What the evidence is good for
Automentic does not certify you. It produces the signed, timestamped evidence that makes these frameworks far less painful to satisfy.
SOC 2
Asks you to evidence access control, change management and monitoring over a period. Automentic supplies a continuous, signed record of who authorised each automated action, instead of a sample assembled before the audit window closes.
ISO 27001
Expects a managed information security system with demonstrable controls. Agent identity, least-privilege authorisation and an immutable action log give you three of those controls operating continuously rather than on paper.
GDPR
Requires accountability for how personal data is processed, and by whom. Because every agent action names its authoriser and its policy, a data subject request or a regulator's question has a factual answer.
Platform security
Zero-trust, applied to machines
The controls below are the ones that matter when the actor is an agent rather than a person: it can run thousands of times an hour, it never gets suspicious, and it will do exactly what a compromised instruction tells it to. So nothing is trusted implicitly, and everything it does leaves a signature.
- Unique cryptographic identity per agent — X.509 or SPIFFE, never a shared account
- Mutual TLS on every agent-to-system channel
- Re-authentication at critical steps, not just at the start of a run
- Least-privilege authorisation evaluated per request, in real time
- Actions signed with the agent's private key for non-repudiation
- Immutable audit trail, exportable to your SIEM
- Revocation takes effect mid-workflow, not at the next restart
Documents
What procurement usually asks for
Data Processing Agreement
Article 28 terms, sub-processor obligations and transfer mechanism. Sent for signature on request.
Sub-processors
Every third party that may process personal data on our behalf, with notice before any change.
Privacy Policy
What we collect through this site, the lawful basis for it, and how long we keep it.
Security questionnaire
Send yours to security@automentic.com and we will complete it, or map it to our standard responses.
Bring your security team
The demo is more useful with the people who will ask the hard questions in the room.