Record
BenchmarkAboutPricing
Book a demo
PlatformWhat Record ManagesITSM for AgentsOnboard AgentsGovernOperateObserve & AuditIntegrations
BenchmarkAboutPricing
Book a demo

Security

Last updated: March 27, 2026

Security is the foundation of the Record platform. We govern AI agents for enterprises where unauthorized access, data leakage, or uncontrolled agent actions are not acceptable. This page describes the security architecture and practices we implement to protect your data and your agents.

Record Gateway and Record Runtime

Connected agents can route model calls, MCP/OpenAPI tools, credentials, policy checks, HITL approvals, audit, and spend through Record Gateway. Managed agents run deeper: Record Runtime adds sandbox lifecycle and three Record-controlled enforcement layers. Each managed layer evaluates the same Cedar policy. If any layer denies an action, execution stops.

  • Runtime layer: Intercepts managed-agent tool calls. Policy checks, human-in-the-loop approval, and credential lease decisions happen before action.
  • Record Gateway: Proxies LLM, MCP, OpenAPI, and agent-to-agent traffic. Enforces content rules, rate limits, model routing, spend caps, and audit context.
  • Sandbox / egress layer: For managed agents, monitors runtime behavior and outbound connections at Record-controlled sandbox and network boundaries. Provides egress-side content enforcement and credential injection.

Just-In-Time Credentials

Agents on Record do not hold standing raw credentials. When an agent needs to access an external service, a just-in-time credential or credential lease is resolved at a trusted Record edge, scoped to the task, and injected by the platform boundary — the agent process receives a governed capability or result, not the raw credential value. Every credential lifecycle event is audit-logged.

For deeper architectural detail (the mechanisms behind each layer, threat model, and sequence diagrams), request our security architecture brief under NDA at security@getrecord.ai.

Encryption

  • In transit: All communications use TLS 1.2 or higher. Inter-service communication uses mutual TLS (mTLS).
  • At rest: All data at rest is encrypted using AES-256. Secrets in the SecretStore are encrypted with a dedicated AES-256 key.

Tenant Isolation

Each customer's data is isolated using row-level security (RLS) in the database, tenant-scoped API tokens, and separate agent containers per tenant. Agents run in unprivileged containers with network namespaces — one tenant's agents cannot access another tenant's data, network, or compute.

Access Control

  • Role-based access control (RBAC): Platform-wide roles (admin, member, viewer) enforced at the API gateway.
  • Cedar policy engine: Fine-grained, attribute-based authorization for agent actions. Policies are versioned, auditable, and fail-closed by default.
  • Human-in-the-loop: Critical agent actions can require explicit human approval before execution, configurable per policy.

Audit and Observability

Every governance decision, tool call, credential lifecycle event, approval, spend event, and policy evaluation is recorded in an audit trail. Gateway traces cover connected agents; managed agents add runtime and sandbox evidence across the three Record Runtime gates. Audit data is available via the web console, CLI, and API.

AI Data Protection

  • Customer data is never used to train, fine-tune, or improve AI models.
  • Prompts and agent interactions are routed through Record Gateway with configurable content filters and PII redaction.
  • You choose which AI model providers your agents use. Record does not send data to providers you have not configured.

Infrastructure

  • Services are containerized and deployed with immutable infrastructure.
  • Production environments use a two-network topology: a public-facing edge network (API only) and an internal network with no external access.
  • No Docker socket access in production. Agent containers run unprivileged.
  • Dependencies are regularly scanned for known vulnerabilities.

Compliance

Record is designed to meet the requirements of SOC 2 Type II, with controls mapped to the Trust Services Criteria. We are committed to achieving formal certification and will update this page as our compliance program progresses.

Incident Response

We maintain an incident response plan that covers detection, containment, eradication, recovery, and post-incident review. In the event of a security incident affecting your data, we will notify you in accordance with applicable laws and our contractual obligations.

Responsible Disclosure

If you discover a security vulnerability in the Record platform, please report it responsibly to security@getrecord.ai. We ask that you give us reasonable time to address the issue before public disclosure. We do not pursue legal action against researchers who act in good faith.

Contact

For security questions, concerns, or to request our security documentation, contact us at security@getrecord.ai.

Record

ITSM for your AI agent workforce.

Platform

  • What Record Manages
  • ITSM for Agents
  • Onboard Agents
  • Governance & Access
  • Observability & Spend
  • Integrations

Resources

  • AI Readiness Benchmark
  • About
  • Pricing

Company

  • Contact
  • Security

Legal

  • Privacy
  • Terms
  • Security

© 2026 Record AI. All rights reserved.

🇺🇸 Made in USA