Trust Center
Security is part of how AIGuardian is built, not a checkbox added after the fact. This page is a straight account of where things stand today.
Security practices
Encryption in transit
HTTPS everywhere with HSTS (two years, includeSubDomains, preload), so browsers refuse to downgrade a connection.
Hardened HTTP headers
X-Content-Type-Options, X-Frame-Options, strict Referrer-Policy, and no X-Powered-By banner disclosing the stack.
Encryption at rest
API keys are stored as SHA-256 hashes and shown once. Tenant model keys are AES-256-GCM encrypted and only ever displayed masked.
Per-tenant isolation
Every tenant's checks, patterns, policies and settings are scoped independently. One tenant's configuration cannot leak into another's.
Safe handling of custom patterns
Regexes you supply are validated before saving and rejected when they contain nested unbounded repetition, so a bad pattern cannot hang the engine.
Prompts are not stored
Prompt content is evaluated in memory and discarded. We persist the decision, check names, latency and token counts. Keeping flagged text is an explicit opt-in per tenant.
Fail-closed enforcement
Hooks block when the service is unreachable or the key is rejected. Availability-first mode is an explicit opt-in flag.
Auditability
Every metered call returns a correlation id that matches its audit row, and every check carries OWASP LLM Top 10 and MITRE ATLAS tags.
Still in progress
- Third-party penetration test and SOC 2 report.
- ML classifiers (PromptGuard, Presidio) alongside the heuristic engine.
- Managed billing; plan changes are currently applied directly from the console.