Security by Default

Security is built into the deployment — not bolted on at procurement.

Every AutomatedAgents team ships with permission-scoped agents, human approval gates, and tenant-isolated infrastructure. Controls exist before the sales call, so your security review confirms what's already live.

Three principles behind every team

These aren't aspirational — they're enforced by the deployment layer every team runs on.

🔒

Least Privilege

Every agent declares a job card with its exact permission surface. A certification gate verifies the agent's tools match the card before the team goes live — stripped terminals, no surprise capabilities, no lateral movement.

👤

Human in the Loop

Irreversible actions — money movement, deletes, public posts, trades — route through approval. An autonomy broker enforces the tier you set per agent. The agents suggest; you approve.

🧱

Tenant Isolation

Each customer runs on a dedicated server with its own agents, memory bus, and integrations. No shared infrastructure between tenants, no cross-customer data paths.

Controls that ship with every team

Each control below is part of the deployed system, not a promise on a slide.

🛂

Job-Card Permission Surfaces

Every agent has a declared permission surface verified before go-live. Customer-facing agents run with restricted tooling: no terminal, no file writes, no code execution — messaging and domain tools only.

Enforced at deployment
⚖️

Autonomy Tiers & Approval Gates

Trivial actions run automatically. Irreversible actions require human approval. You set the autonomy tier per agent, and the broker enforces it on every action.

broker.py
📱

SMS Access Control

Teams are reachable by text via Twilio — but only from approved numbers. Access is default-deny: unauthorized senders cannot reach agents or trigger actions.

Default deny
🛡️

Prompt-Injection Hardening

Agent system definitions include anti-injection guardrails so external content — emails, web pages, tickets — can't redirect an agent outside its role.

Built into agent definitions
🕸️

Mesh Orchestration & Audit

A synchronous orchestrator ticks across the team, validating every agent reported in and checking shared budgets before jobs fire. Actions are logged and traceable.

Mesh orchestrator
🧠

Team-Scoped Memory

Agents share a structured memory bus with handoff schemas — scoped to the team and tenant. Agents start each session knowing what the team already decided, with no cross-tenant bleed.

Mnemosyne
🚨

Hard Risk Rules + Kill Switch

Trading teams enforce fixed loss caps, trailing drawdown limits, and concentration limits — and a kill switch halts all new orders the moment a limit breaches. Risk limits are structural, not aspirational.

Trading teams
📜

Governance Playbooks

Structured playbooks govern how work flows through the team — request-to-handoff, safe feature changes, incident response, weekly ops reviews. Agents know their evidence boundaries and when to escalate.

OMH governance layer

Certification status — straight answer

We'd rather tell you exactly where we are than let you discover it mid-procurement.

Where we are today

AutomatedAgents is not yet SOC 2 or ISO 27001 certified. We're building toward SOC 2 Type I/II as the first certification, because that's the framework US buyers actually ask for.

Questions about our security posture?

Our security and compliance contact responds directly — no ticket black hole.

Contact Security → Deploy Your Team