Skip to main content
Compliance & Audit

Evidence, not assurances

A tamper-evident record of everything agents do, retention up to unlimited, and the evidence auditors ask for.

The record

Every decision logged immutably

Every token access and provider call is recorded with the policy decision that allowed or denied it, and full attribution: organization, app, user, agent, trace id. Rows are append-only, hash-linked for tamper detection, and blocked from updates at the database layer. Success and failure paths both land in the trail.

  • Real-time streaming to Splunk-compatible and OCSF webhook SIEM endpoints
  • Structured events you can filter, query, and alert on
  • A denial names the policy that fired
Live Event Stream
14:32:07sarah@github.contents.writeALLOW
14:31:58sarah@linear.issue.createALLOW
14:31:42sarah@datadog.logs.readALLOW
14:31:15mike@aws.s3.deleteBucketDENY
14:30:51dev-botpostgres.query.readALLOW
14:30:33mike@github.repo.settingsESCALATE
Retention

Kept as long as you need, provably intact

Retention is an organization-wide window you can extend, up to unlimited. Legal hold suspends deletion for a matter. Exports cover a chosen scope and time range, and the hash chain shows nothing was altered along the way.

  • Org-wide retention, extendable to unlimited
  • Legal hold for active matters
  • Evidence export on demand
Evidence export
Retention: unlimitedLegal hold: offStream: Splunk
token.retrieved · billing-agent14:02:11
access_denied_policy · support-bot14:02:38
approval.approved · finance-ops14:03:05
chain verified · sha256:9f2c…e1a7

What auditors ask for

Audit log export

Every credential access, policy decision, and provider call for the period under review, exportable on demand.

Identity provider configuration

Confirmation that JWT verification is enforced against your IdP.

Policy configuration

The gating in place on sensitive grants: approvals, restrictions, content rules.

Key rotation evidence

The trail contains every mint, deprecate, and revoke event.

How the platform itself is secured

  • Credentials live in a dedicated secret store, encrypted at rest, with keys managed outside the application database
  • Fail-closed authorization: if a policy cannot be evaluated, the request is denied
  • Zero-trust ownership: a key confers no capability without an explicit record naming it
  • Postgres holds metadata and vault references; provider tokens and credentials live only in the vault
  • Per-key isolation, plaintext credentials never in logs and never returned to application code

Controls monitored continuously

SOC 2 in progress

Our trust center publishes the live state of our security program: monitored controls across access, data protection, infrastructure, vulnerability management, and incident response, plus an independent penetration test within the last 12 months. Security policy documents are available there on request. A SOC 2 audit is in progress.

Visit the trust center (opens in a new tab)

Reporting a vulnerability

Found something? We want to know, and we review every report. Emailsecurity@alterauth.comwith enough detail to reproduce the issue.

Data handling

How we process data is documented, versioned, and public: thePrivacy Policy, theData Processing Agreement, and oursub-processors.

Ready to secure your agents?

Book a 30-minute walkthrough with the founders.

Necessary

Required for sign-in, security, authorization, and remembering your choices.

Always active

Analytics

Helps us understand which product and documentation features are useful.

Performance diagnostics

Uses performance tracing and privacy-masked session replay to diagnose problems.

You can change these choices at any time from Cookie settings.