Security & Trust
Security & trust at Behavry.
The independent system of record for autonomous agents. Independent because the Decision Trace is signed by a control plane the agent, its vendor, and your SIEM cannot reach. Verify one yourself, offline, with no Behavry in the loop. SOC 2 & ISO 27001 control mapping complete · offline-verifiable Decision Trace · security@behavry.ai. Download the whitepaper →
Verify any Decision Trace offline. No Behavry in the loop.
Every audit event is Ed25519-signed and SHA-256 hash-chained to the one before it. Export bundles carry a Merkle root over the full timeline. Drop an evidence package into verify.behavry.ai: nothing you submit is stored, logged, or forwarded, it is checked in memory and discarded. Bring your own trust anchor and the result doesn't depend on trusting us at all.
$ python tools/verify_event.py \
--bundle behavry-audit-export.json \
--trust-anchor behavry-trust-anchor.json
✓ manifest signature verified (Ed25519)
✓ merkle root matches 1,204 events
✓ hash chain intact · 0 breaks
✓ per-event signatures verified
# air-gapped · no live KMS · no Behavry DB · runs entirely on your machine
Every event carries a per-row Ed25519 signature. Not just the export bundle.
Each event hashes the one before it. Edit history anywhere, and every hash after it breaks.
You pin the public key. We never ask you to trust our service to check our own work.
You supply the issuing tenant's behavry-trust-anchor.json, handed to you out-of-band. Behavry is not in the loop.
Pin the tenant's Ed25519 key directly, no anchor file needed. Same independence, one fewer file to manage.
Supply no anchor and we look the signing key up ourselves. That confirms internal consistency, but the key came from Behavry. This is Behavry vouching for Behavry.
Five properties any security review starts with.
Structurally separate from the agents and vendors it governs. The actor cannot attest to itself.
SHA-256 hash-chained events. Alter history anywhere and every hash after it breaks.
Every tenant's agents, policies, alerts, and audit events are isolated at the query level.
TLS on every hop, AES-256-GCM at rest, short-lived RS256-signed tokens on every request.
White-box, OWASP WSTG-aligned testing. Every finding tracked to remediation and re-verified.
Where we actually stand. No badges we haven't earned.
We only show a “certified” badge when it's literally true. Below is the honest state of our compliance program today.
| Framework | Status | Detail |
|---|---|---|
| SOC 2 Trust Services Criteria |
CONTROL MAPPING COMPLETE | CC6–CC8 (Security) mapped, with supporting CC9 (Availability) controls. Independent Type II audit is on the roadmap. Not yet complete. |
| ISO/IEC 27001:2022 Information security management |
MAPPED | A.5.24, A.8.2, A.8.15, A.8.16, A.8.24 mapped to shipped controls. Certification has not been pursued yet. |
| Framework crosswalks Buyer & regulator frameworks |
LIVE | FSI (OCC SR 11-7 · NYDFS 23 NYCRR 500 · SEC 206(4)-7 · SEC 204-2 · Reg S-P) · OWASP ASI · HITRUST AI · CIS AI/ML · NIST AI RMF · PCI DSS v4.0 · EU AI Act · GDPR · HIPAA. |
What “mapped” means. We do not claim SOC 2 or ISO 27001 certification. “Mapped” and “control mapping complete” mean our shipped controls satisfy the named clauses today, not that an independent auditor has certified them. When that changes, this page changes with it.
Compliance mappings last reviewed April 2026 · Page published July 21, 2026.
What we actually capture. And what we never do.
Tool name, action, resource path, policy decision, DLP pattern + severity, and a SHA-256 hash of the input. Never the prompt, file contents, or query results themselves.
The MCP proxy and the OpenAI / Anthropic model proxies never see your prompts or completions, only metadata about them. A compromised Behavry database leaks governance signal, not your data.
TLS on every hop; AES-256-GCM for stored payloads; short-lived, RS256-signed tokens for every request.
Configure your own retention window. Erasure requests are honored by anonymizing records in place, so the hash chain, and its tamper evidence, stays intact.
Who else touches the data.
| Vendor | What it touches |
|---|---|
| AWS | Cloud infrastructure & hosting |
| Google Cloud | Infrastructure & workspace services |
| Microsoft | Enterprise SSO (Entra ID / OIDC) integration |
| DigitalOcean | Infrastructure & hosting |
| Clerk | Admin identity & authentication (OIDC) |
| Anthropic | Claude model API. Metadata-only proxy, no prompt/completion content |
| OpenAI | GPT model API. Metadata-only proxy, no prompt/completion content |
| Timescale (TimescaleDB) | Audit log database |
Full sub-processor list with data-flow detail is available under NDA: security@behavry.ai.
Get what your review actually needs.
The full architecture, integrity model, and compliance mapping in one branded PDF.
Available on request for teams running a standard vendor questionnaire.
API reference, integration guides, and deployment options.
Found something? Tell us first.
Report suspected vulnerabilities to security@behavry.ai. Details for automated tooling are published at /.well-known/security.txt per RFC 9116.
- We acknowledge every report within 2 business days.
- Good-faith testing against your own account or data, without service disruption or data destruction, will not trigger legal action from us.
- We'll keep you updated as we investigate and remediate, and credit researchers who ask to be named.
- Every finding, internal or external, is tracked to remediation and, where applicable, independently re-tested.
System status.
Live uptime, incidents, and maintenance windows.
Security review in progress? Skip the first three emails and talk to us directly: security@behavry.ai.
Nothing to take on faith but the math.
BOOK A BRIEFING →