🛡AIGuardian

Trust Center

Security is part of how AIGuardian is built, not a checkbox added after the fact. This page is a straight account of where things stand today.

Security practices

Encryption in transit

HTTPS everywhere with HSTS (two years, includeSubDomains, preload), so browsers refuse to downgrade a connection.

Hardened HTTP headers

X-Content-Type-Options, X-Frame-Options, strict Referrer-Policy, and no X-Powered-By banner disclosing the stack.

Encryption at rest

API keys are stored as SHA-256 hashes and shown once. Tenant model keys are AES-256-GCM encrypted and only ever displayed masked.

Per-tenant isolation

Every tenant's checks, patterns, policies and settings are scoped independently. One tenant's configuration cannot leak into another's.

Safe handling of custom patterns

Regexes you supply are validated before saving and rejected when they contain nested unbounded repetition, so a bad pattern cannot hang the engine.

Prompts are not stored

Prompt content is evaluated in memory and discarded. We persist the decision, check names, latency and token counts. Keeping flagged text is an explicit opt-in per tenant.

Fail-closed enforcement

Hooks block when the service is unreachable or the key is rejected. Availability-first mode is an explicit opt-in flag.

Auditability

Every metered call returns a correlation id that matches its audit row, and every check carries OWASP LLM Top 10 and MITRE ATLAS tags.

Still in progress