Evidence, not assurances
A tamper-evident record of everything agents do, retention up to unlimited, and the evidence auditors ask for.
Every decision logged immutably
Every token access and provider call is recorded with the policy decision that allowed or denied it, and full attribution: organization, app, user, agent, trace id. Rows are append-only, hash-linked for tamper detection, and blocked from updates at the database layer. Success and failure paths both land in the trail.
- Real-time streaming to Splunk-compatible and OCSF webhook SIEM endpoints
- Structured events you can filter, query, and alert on
- A denial names the policy that fired
Kept as long as you need, provably intact
Retention is an organization-wide window you can extend, up to unlimited. Legal hold suspends deletion for a matter. Exports cover a chosen scope and time range, and the hash chain shows nothing was altered along the way.
- Org-wide retention, extendable to unlimited
- Legal hold for active matters
- Evidence export on demand
What auditors ask for
Audit log export
Every credential access, policy decision, and provider call for the period under review, exportable on demand.
Identity provider configuration
Confirmation that JWT verification is enforced against your IdP.
Policy configuration
The gating in place on sensitive grants: approvals, restrictions, content rules.
Key rotation evidence
The trail contains every mint, deprecate, and revoke event.
How the platform itself is secured
- Credentials live in a dedicated secret store, encrypted at rest, with keys managed outside the application database
- Fail-closed authorization: if a policy cannot be evaluated, the request is denied
- Zero-trust ownership: a key confers no capability without an explicit record naming it
- Postgres holds metadata and vault references; provider tokens and credentials live only in the vault
- Per-key isolation, plaintext credentials never in logs and never returned to application code
Controls monitored continuously
SOC 2 in progressOur trust center publishes the live state of our security program: monitored controls across access, data protection, infrastructure, vulnerability management, and incident response, plus an independent penetration test within the last 12 months. Security policy documents are available there on request. A SOC 2 audit is in progress.
Visit the trust center (opens in a new tab)Reporting a vulnerability
Found something? We want to know, and we review every report. Emailsecurity@alterauth.comwith enough detail to reproduce the issue.
Data handling
How we process data is documented, versioned, and public: thePrivacy Policy, theData Processing Agreement, and oursub-processors.
Ready to secure your agents?
Book a 30-minute walkthrough with the founders.
