The independent system of record for autonomous behavior — verifiable by anyone, trusted by design.
Every audit event is Ed25519-signed and SHA-256 hash-chained to the one before it. Export bundles carry a Merkle root over the full timeline. Point our open verifier at a public key you pin yourself, and check the record against a customer-supplied trust anchor — no Behavry API, no Behavry database, nothing to take on faith but the math.
Structurally separate from the agents and vendors it governs — the actor cannot attest to itself.
SHA-256 hash-chained events. Alter history anywhere and every hash after it breaks.
Every tenant's agents, policies, alerts, and audit events are isolated at the query level.
TLS on every hop, AES-256-GCM at rest, short-lived RS256-signed tokens on every request.
White-box, OWASP WSTG-aligned testing. Every finding tracked to remediation and re-verified.
We only show a "certified" badge when it's literally true. Below is the honest state of our compliance program today.
CC6–CC8 (Security) mapped, with supporting CC9 (Availability) controls. Independent Type II audit is on the roadmap — not yet complete.
A.5.24, A.8.2, A.8.15, A.8.16, A.8.24 mapped to shipped controls. Certification has not been pursued yet.
FSI (OCC SR 11-7 · NYDFS 23 NYCRR 500 · SEC 206(4)-7 · SEC 204-2 · Reg S-P) · OWASP ASI · HITRUST AI · CIS AI/ML · NIST AI RMF · PCI DSS v4.0 · EU AI Act · GDPR · HIPAA.
We do not claim SOC 2 or ISO 27001 certification. "Mapped" and "control mapping complete" mean our shipped controls satisfy the named clauses today — not that an independent auditor has certified them. When that changes, this page changes with it.
Compliance mappings last reviewed April 2026 · Page published July 21, 2026.
Tool name, action, resource path, policy decision, DLP pattern + severity, and a SHA-256 hash of the input — never the prompt, file contents, or query results themselves.
The MCP proxy and the OpenAI / Anthropic model proxies never see your prompts or completions — only metadata about them. A compromised Behavry database leaks governance signal, not your data.
TLS on every hop; AES-256-GCM for stored payloads; short-lived, RS256-signed tokens for every request.
Configure your own retention window. Erasure requests are honored by anonymizing records in place, so the hash chain — and its tamper evidence — stays intact.
| Vendor | What it touches |
|---|---|
| AWS | Cloud infrastructure & hosting |
| Google Cloud | Infrastructure & workspace services |
| Microsoft | Enterprise SSO (Entra ID / OIDC) integration |
| DigitalOcean | Infrastructure & hosting |
| Clerk | Admin identity & authentication (OIDC) |
| Anthropic | Claude model API — metadata-only proxy, no prompt/completion content |
| OpenAI | GPT model API — metadata-only proxy, no prompt/completion content |
| Timescale (TimescaleDB) | Audit log database |
Full sub-processor list with data-flow detail is available under NDA — security@behavry.ai.
The full architecture, integrity model, and compliance mapping in one branded PDF.
Download PDF →API reference, integration guides, and deployment options.
docs.behavry.ai →Report suspected vulnerabilities to security@behavry.ai. Details for automated tooling are published at /.well-known/security.txt per RFC 9116.
Skip the first three emails. Talk to us directly.
Email Security →