Trust center

Security Boundaries That Follow The Work.

Proovable AI is built for multi-tenant agent operations. Authentication, authorization, tenant isolation, audit capture, and rate controls are enforced in the application path.

Posture

Controls Built Into The Platform

lock

Identity And Access

Authentication uses Microsoft Entra ID. Role-based permissions determine which people can view, change, approve, run, and govern work.

badge

Tenant Isolation

Tenant-scoped records are enforced through SQL row-level security and application-level query filters. Tenant context follows each request.

visibility_off

Security Controls In The Request Path

HTTPS enforcement, security headers, correlation IDs, rate limits, authorization, IP allowlists, and idempotency controls operate before protected endpoints execute.

groups

Auditable Actions

Important actions create an audit record. Policy violations, approvals, changes, and incident activity retain their history rather than overwriting it.

schedule

Secret And Key Handling

Production secrets are supplied through managed identity and Azure Key Vault references, not application configuration files.

dns

API And Embed Safeguards

Public and embedded agent surfaces validate their own access path and apply origin, authentication, rate, and tenant controls.

Subprocessors

Security That Is Observable

policy

Policy Enforcement

Policies can restrict data handling, topics, tools, access, approval requirements, models, and spend. Violations can block, redact, notify, or escalate.

account_tree

Evidence And Attestation

Append-only audit records and attestation capabilities support reviewable evidence for governed agent activity and system changes.

Security is not a separate report. It is the set of boundaries that determine who can act, what can run, and what the organization can later verify.