Security & Trust
Guardyx AI is infrastructure that sits in the path of real actions.
So we hold it to an infrastructure standard.

Every action Guardyx AI governs — allowed, held, or denied — lands here and exports as a tamper-evident evidence pack.
Deployment
Run Guardyx AI as hosted SaaS, or self-hosted in your own VPC or on-prem — whichever your security posture calls for.
Encryption
TLS 1.2+ in transit. KMS at rest. Credentials double-encrypted, keys in Secrets Manager.
- In transit
- TLS 1.2 or higher
- At rest
- AWS KMS
- Credentials
- AES-128-CBC + HMAC, on top of KMS
- Key storage
- AWS Secrets Manager — never in code
- Agent auth secrets
- One-way SHA-256 hashes
- Key rotation
- Staged, no downtime
Full statementon Encryption
Encrypted in transit and at rest. All traffic uses TLS 1.2 or higher. Data is encrypted at rest with AWS KMS, and credentials get a second layer of application-level encryption (AES-128-CBC + HMAC) with keys held in AWS Secrets Manager — never in code. Agent authentication secrets are stored as one-way SHA-256 hashes, not encrypted. Encryption keys support staged rotation with no downtime.
Data retention
Governance evidence is retained for 730 days by default, and never longer. Searchable history depends on your plan; tool-call content has a separate retention window. Every purge attested.
- Evidence default
- 730 days (two years)
- Evidence maximum
- 730 days — shorten it, never extend it
- Indefinite retention
- Not an option
- High-risk floor
- 183 days (EU AI Act Art. 26(6))
- Enforcement
- Database-level constraints
- Tiers
- Governance evidence vs. tool-call content
Full statementon Data retention
You set the window; the schema enforces it. Every workspace has an explicit governance-evidence retention period — indefinite retention isn't an option. The default is 730 days, which is also the ceiling: a workspace can shorten its window, never extend it. Database-level constraints mean a misconfiguration can't silently destroy your trail. Workspaces that self-declare as high-risk AI deployers get a 183-day floor, matching EU AI Act Article 26(6). Searchable audit history is a separate plan entitlement: 7 days on Free, 90 days on paid plans, and longer for Enterprise as agreed, within the evidence retention window. Expiration of searchable history does not itself delete stored evidence, and a longer history entitlement cannot restore deleted records. The Terms specify a 90-day storage minimum unless an Order Form or DPA provides otherwise; shorter configured windows must be consistent with that agreement and applicable minimums. Retention is two-tier: keep governance evidence for years while scrubbing tool-call content on a shorter clock. Every purge is attested by a retained, hash-chained record — and a purge aborts entirely if audit-chain verification fails, so cleanup can never destroy evidence of tampering.
Data residency
All customer data is stored in AWS US East (N. Virginia, us-east-1). We do not currently offer regional data residency options.
Data handling & isolation
Row-level workspace scoping on every record, query, and export.
- Scoping
- Row-level, per workspace
- Queries & exports
- Filtered to the calling workspace
- Admin endpoints
- Role-gated
- What is recorded
- Tool calls, including arguments and results
- Content retention
- Controlled independently of audit metadata
Full statementon Data handling & isolation
Every record is scoped to your workspace at the row level, and every query and export is filtered to the calling workspace. Administrative endpoints are role-gated. Guardyx AI records the tool calls your agents make, including call arguments and results — that's the evidence the product exists to produce — and you control how long that content is kept independently of the surrounding audit metadata.
Audit trail integrity
Tamper-evident: a per-workspace SHA-256 hash chain, verified on demand.
- Method
- Per-workspace SHA-256 hash chain
- Detection
- Pinpoints the exact modified record
- Verification
- On demand, embedded in every evidence pack
Full statementon Audit trail integrity
Your audit trail is tamper-evident. Every governance event is linked into a per-workspace SHA-256 hash chain, so any after-the-fact modification is detectable at the exact record. Verification runs on demand and its result is embedded in every evidence pack you export.
Identity & access
Sign in with your own identity provider over OIDC, with role-based access control (RBAC) across the portal and administrative actions.
Approvals
Route approvals to the Guardyx AI portal, Slack, or email — wherever your team already works.
SIEM & observability
We don't currently stream into a security information and event management (SIEM) tool or an observability platform, and we'd rather say so than imply otherwise. Every governed action is captured and can be exported as an auditor-ready evidence pack, with audit-chain verification embedded in the export.
Compliance
Guardyx AI maps to ISO/IEC 42001, NIST AI RMF, and ISO/IEC 27001 Annex A — and produces the evidence for them on demand, as an auditor-ready pack rather than a questionnaire response.
- ISO/IEC 42001
- Mapped
- NIST AI RMF
- Mapped
- ISO/IEC 27001
- Annex A mapped
- Evidence format
- Auditor-ready pack, on demand
Bring your security team. We'd rather answer the hard questions early.
Run Guardyx AI hosted, or entirely inside your own environment.