Trust and operationsTrust and compliance

Trust and compliance

Use this page for security review and rollout approval. It summarizes the AgentKeeper trust model and links to the detailed controls that answer privacy, evidence, enforcement, and audit questions.

Use this page for security review and rollout approval. It summarizes the AgentKeeper trust model and links to the detailed controls that answer privacy, evidence, enforcement, and audit questions.

Trust model

AreaAgentKeeper position
Control planeAgentKeeper evaluates AI-agent actions against organization policy and records evidence for Activity and investigations.
Endpoint runtimeLocal hooks, runtime services, browser extension policy, and MCP Gateway collect evidence where each source supports it.
EnforcementBlocking is available only on supported pre-execution hook or gateway paths. Event-only and after-only paths provide visibility, warning, and investigation evidence.
Fail-openLocal integrations should avoid breaking developer workstations during transient service or network failures. Health must make degraded coverage visible.
IdentityWorkstation, API key, SSO, Directory Sync, MDM, and source-tool evidence combine to improve attribution. Do not treat one signal as perfect identity by itself.

Data boundaries

AgentKeeper should collect the smallest evidence needed to explain policy and investigations:

  • Runtime source, hostname, workstation, session, repository, path, domain, command, MCP server/tool, verdict, and policy context where available.
  • Redacted summaries and hashes where raw evidence is not needed.
  • Raw prompts or richer tool output only when the organization enables the relevant retention or deep-capture mode.
  • Prompt Vault sealed evidence when raw prompt retention is enabled but reveal should require owner/admin approval and audit.

See Data handling, What AgentKeeper sees, and Prompt Vault.

Compliance evidence

EvidenceWhere to validate
Runtime policy decisionsActivity and investigations
Workstation and setup healthWorkstations and Validate deployment
Prompt retention and reveal controlsData handling and Prompt Vault admin settings
Control integrity and tamper evidenceControl integrity
API and export boundariesAPI Reference
Webhook deliveryWebhooks
SSO and Directory SyncAuthentication and Directory Sync

Security review checklist

Before approving a fleet rollout, record:

  1. Production AgentKeeper origin and any private endpoint.
  2. Network and TLS inspection decision from Network requirements.
  3. MDM package version, checksum, signer/notarization status where applicable, and assignment name.
  4. API key and enrollment-token handling model.
  5. Prompt retention, Deep Capture, and Prompt Vault mode.
  6. Owner/admin list for policy, access, evidence reveal, and exports.
  7. One successful live event and one known BLOCK for each enforced source.
  8. Rollback and uninstall evidence for each OS.

Assurance artifacts

SOC 2, ISO, penetration-test summaries, data processing addenda, subprocessors, and data residency commitments are contract and trust-center artifacts. Keep those artifacts in the customer security review packet and link this docs page as the product-control map.