Enterprise-grade by architecture, not by checklist.
The security posture is a consequence of the platform's shape — not a layer painted on at the end. Customer-owned storage, policy-as-code at every boundary, audit trails by default.
Customer-owned data plane
Your data lives in your S3, your Azure Blob, your GCS — never on Eisberg infrastructure. We bring the control plane and compute. You bring the keys.
Customer-key encryption, fail-closed
TLS 1.3 in transit. At rest, your data AND its catalog metadata land in your bucket encrypted with your own KMS key, fail-closed by design: if your key can't be honored, the platform refuses to write rather than write plaintext. Verified in our live environment.
Policy-as-code governance, every layer
Every query funnels through one governed chokepoint, on by default. Role-based column masking verified in our live environment — a viewer sees ****, an authorized role sees the value. Postgres row-level security enforced under a non-superuser role. Cross-tenant isolation verified in our live environment: foreign credentials are denied, zero leakage.
Tamper-evident audit trail
Every query, every action, every agent decision lands in an HMAC-chained audit log — each event cryptographically bound to the one before it. Chain integrity is verifiable on demand via a live API, not a promise in a PDF.
Lineage that survives migrations
Column-level lineage recorded at write time, persisted with your data plane. Iceberg time travel for point-in-time reproducibility. Replay any decision, any pipeline, any agent action — by ID.
Compliance rule packs as code (in development)
Regulated-framework rule packs — BCBS 239, SR 11-7, HIPAA and more — are being built as deployable code modules on the governance plane, with generated audit evidence. In development with design partners; these are modules, not certifications, and we say so.
Six guardrails the rest of the industry treats as optional.
Agents are about to become the primary users of every data system on earth. Most platforms are not ready for that. Ours was designed for it.
- Per-agent identity via signed Birth Certificates, enforced at compile time — a failed certificate means the action never runs
- Impact-as-a-gate: predicted blast radius stops a consequential action before execution; two-key human approval clears it
- Graduated autonomy: agents earn trust through verified successful actions, never granted by default
- Per-action metering surfaces every agent decision in the billing trail
- Agent audit log is queryable, filterable, and exportable for regulator review
- Hard kill switch: revoke an agent's permissions globally in one API call
What we are pursuing in the next 12 months.
Planned
SOC 2 Type II
Planned
ISO 27001
Planned
HIPAA BAA
Planned
FedRAMP Moderate
Need the full security package?
CISO whitepaper, threat model, agent governance specification, policy library, and audit trail schema — all available under NDA.