Security & Trust

Security & trust at Behavry.

The independent system of record for autonomous agents. Independent because the Decision Trace is signed by a control plane the agent, its vendor, and your SIEM cannot reach. Verify one yourself, offline, with no Behavry in the loop. SOC 2 & ISO 27001 control mapping complete · offline-verifiable Decision Trace · security@behavry.ai. Download the whitepaper →

/001 · THE OPEN-VERIFIER PROMISEBEHAVRY · RECORD

Verify any Decision Trace offline. No Behavry in the loop.

Every audit event is Ed25519-signed and SHA-256 hash-chained to the one before it. Export bundles carry a Merkle root over the full timeline. Drop an evidence package into verify.behavry.ai: nothing you submit is stored, logged, or forwarded, it is checked in memory and discarded. Bring your own trust anchor and the result doesn't depend on trusting us at all.

VERIFY A PACKAGE NOW → GET A SAMPLE PACKAGE →
$ python tools/verify_event.py \
    --bundle behavry-audit-export.json \
    --trust-anchor behavry-trust-anchor.json

✓ manifest signature verified (Ed25519)
✓ merkle root matches 1,204 events
✓ hash chain intact · 0 breaks
✓ per-event signatures verified

# air-gapped · no live KMS · no Behavry DB · runs entirely on your machine
Signed

Every event carries a per-row Ed25519 signature. Not just the export bundle.

Hash-chained

Each event hashes the one before it. Edit history anywhere, and every hash after it breaks.

Trust-anchored

You pin the public key. We never ask you to trust our service to check our own work.

Your trust anchor · strongest

You supply the issuing tenant's behavry-trust-anchor.json, handed to you out-of-band. Behavry is not in the loop.

A raw public key · strongest

Pin the tenant's Ed25519 key directly, no anchor file needed. Same independence, one fewer file to manage.

The published registry · convenience only

Supply no anchor and we look the signing key up ourselves. That confirms internal consistency, but the key came from Behavry. This is Behavry vouching for Behavry.

/002 · SECURITY OVERVIEWFIVE PROPERTIES

Five properties any security review starts with.

Independence by design

Structurally separate from the agents and vendors it governs. The actor cannot attest to itself.

Tamper-evident record

SHA-256 hash-chained events. Alter history anywhere and every hash after it breaks.

Tenant isolation

Every tenant's agents, policies, alerts, and audit events are isolated at the query level.

Encryption everywhere

TLS on every hop, AES-256-GCM at rest, short-lived RS256-signed tokens on every request.

Independent pen-testing

White-box, OWASP WSTG-aligned testing. Every finding tracked to remediation and re-verified.

/003 · COMPLIANCE STATUSNO UNEARNED BADGES

Where we actually stand. No badges we haven't earned.

We only show a “certified” badge when it's literally true. Below is the honest state of our compliance program today.

FrameworkStatusDetail
SOC 2
Trust Services Criteria
CONTROL MAPPING COMPLETE CC6–CC8 (Security) mapped, with supporting CC9 (Availability) controls. Independent Type II audit is on the roadmap. Not yet complete.
ISO/IEC 27001:2022
Information security management
MAPPED A.5.24, A.8.2, A.8.15, A.8.16, A.8.24 mapped to shipped controls. Certification has not been pursued yet.
Framework crosswalks
Buyer & regulator frameworks
LIVE FSI (OCC SR 11-7 · NYDFS 23 NYCRR 500 · SEC 206(4)-7 · SEC 204-2 · Reg S-P) · OWASP ASI · HITRUST AI · CIS AI/ML · NIST AI RMF · PCI DSS v4.0 · EU AI Act · GDPR · HIPAA.

What “mapped” means. We do not claim SOC 2 or ISO 27001 certification. “Mapped” and “control mapping complete” mean our shipped controls satisfy the named clauses today, not that an independent auditor has certified them. When that changes, this page changes with it.

Compliance mappings last reviewed April 2026 · Page published July 21, 2026.

/004 · DATA HANDLINGMETADATA, NOT CONTENT

What we actually capture. And what we never do.

Metadata, not content

Tool name, action, resource path, policy decision, DLP pattern + severity, and a SHA-256 hash of the input. Never the prompt, file contents, or query results themselves.

Content capture is off by default

The MCP proxy and the OpenAI / Anthropic model proxies never see your prompts or completions, only metadata about them. A compromised Behavry database leaks governance signal, not your data.

Encrypted in transit and at rest

TLS on every hop; AES-256-GCM for stored payloads; short-lived, RS256-signed tokens for every request.

Retention is yours to set

Configure your own retention window. Erasure requests are honored by anonymizing records in place, so the hash chain, and its tamper evidence, stays intact.

/005 · SUB-PROCESSORSBEHAVRY · RECORD

Who else touches the data.

VendorWhat it touches
AWSCloud infrastructure & hosting
Google CloudInfrastructure & workspace services
MicrosoftEnterprise SSO (Entra ID / OIDC) integration
DigitalOceanInfrastructure & hosting
ClerkAdmin identity & authentication (OIDC)
AnthropicClaude model API. Metadata-only proxy, no prompt/completion content
OpenAIGPT model API. Metadata-only proxy, no prompt/completion content
Timescale (TimescaleDB)Audit log database

Full sub-processor list with data-flow detail is available under NDA: security@behavry.ai.

/006 · DOCUMENTATION & QUESTIONNAIRESFOR YOUR REVIEW

Get what your review actually needs.

Security whitepaper

The full architecture, integrity model, and compliance mapping in one branded PDF.

DOWNLOAD PDF →

SIG-Lite / CAIQ

Available on request for teams running a standard vendor questionnaire.

REQUEST →

Technical documentation

API reference, integration guides, and deployment options.

DOCS.BEHAVRY.AI →

/007 · RESPONSIBLE DISCLOSURERFC 9116

Found something? Tell us first.

Report suspected vulnerabilities to security@behavry.ai. Details for automated tooling are published at /.well-known/security.txt per RFC 9116.

  • We acknowledge every report within 2 business days.
  • Good-faith testing against your own account or data, without service disruption or data destruction, will not trigger legal action from us.
  • We'll keep you updated as we investigate and remediate, and credit researchers who ask to be named.
  • Every finding, internal or external, is tracked to remediation and, where applicable, independently re-tested.
/008 · STATUSLIVE

System status.

Live uptime, incidents, and maintenance windows.

status.behavry.ai →

Security review in progress? Skip the first three emails and talk to us directly: security@behavry.ai.

Nothing to take on faith but the math.

BOOK A BRIEFING →