The AI Security Layer for enterprise: API security, MCP security, AI gateway, and verification engine — unified under one correlation ID with tamper-evident hash-chain audit, Patroni HA and Helm charts for customer-hosted deployments, and 12 compliance frameworks with automated assessment (plus 8 reference catalogs). All 4 pillars, custom-quoted (Contact Sales — priced to your scale and compliance needs).
Built for regulated industries with compliance, scale, and security at the core
Auto-generated SOC 2, HIPAA, and PCI evidence packages. A published control crosswalk maps each SOC 2 control to its overlapping ISO 27001 and HIPAA controls.
SSO/SAML sign-in is not yet available. Multi-tenant administration with organization-level isolation and SAML XML Signature Wrapping (XSW) defense.
Cloud, on-premise, or air-gapped deployment. Deploy in the region you choose for data residency, with a dedicated VPC, private endpoints, and high availability from the shipped Helm charts and Patroni PostgreSQL.
Enterprise plans include unlimited access to all 4 pillars of the G8KEPR platform
Every state-changing operation is appended to a SHA-256 hash-chained audit log. Control crosswalk: each SOC 2 control is mapped to its overlapping ISO 27001 and HIPAA controls.
"-Ready" / "aligned" / "controls implemented" reflect capability posture. SOC 2 Type II, HIPAA, ISO 27001 certifications pending external audit. Audit retention: 90 days hot (PostgreSQL monthly partitions), 7 years cold (S3 WORM Object Lock COMPLIANCE mode).
Aligned with the Starter / Pro / Enterprise tiers on our pricing page. Contractual SLA ships with the Master Service Agreement.
Patroni HA and Helm charts ship for customer-hosted deployments. Kubernetes-native. No DIY required.
For customer-hosted deployments: PostgreSQL with Patroni + etcd + HAProxy quorum-based failover (a 2026-09-18 drill measured 31.7 s to the next acknowledged write, with 0 of 1,028 acknowledged writes lost), uvicorn workers with process-level isolation, and Nginx upstream health checks. The hosted service runs on a single node without them.
Helm charts for the platform, the collector and the sensors, and an AWS Terraform module (VPC, RDS, ElastiCache, KMS, Secrets Manager) ship for customer-hosted installs. The module provisions the infrastructure; installing the platform onto it is the separate Helm step.
CodeQL, Trivy container scanning, Bandit, pip-audit + npm audit, OWASP ZAP, Gitleaks, Semgrep SAST and Lighthouse are all defined in the repository. Hosted CI is paused for cost, so 10 workflows are active and the rest are disabled with a dated reason in docs/ci/04-workflow-dispositions.md; the gates, including the held-out detection test, are run locally.
4-dimension composite score (device 25% / location 25% / behavior 30% / time 20%), computed and recorded on every login, with impossible-travel detection via Haversine. Elevated scores are logged for review; the allow / monitor / step-up / deny bands are reported, not yet enforced on the login or request path.
Six Helm manifests: Deployment with rolling updates, HorizontalPodAutoscaler, PodDisruptionBudget, NetworkPolicy, ExternalSecrets, PrometheusRule. SHA-pinned images, non-root containers, defined HEALTHCHECK.
SHA-256 hash chain with all-zeros genesis block. Three verification levels (full / single / last-N). Monthly-partitioned PostgreSQL with 84-month retention. WORM Object Lock COMPLIANCE mode for cold storage.
Your success is our priority. Get dedicated support from security experts.
Your own engineer who knows your infrastructure inside and out. Available via Slack, email, or phone.
Pro tier ships a 99.9% availability target with a ~43 minute monthly downtime budget. Enterprise tier negotiates a custom SLA per Master Service Agreement.
Quarterly security reviews with our founding team. Direct Slack channel for strategic guidance and roadmap input.
Simple, transparent pricing for enterprise teams
Custom pricing, quoted to your scale, deployment model (VPC, on-prem, or air-gapped), and compliance needs. All 4 pillars, BAA/DPA, and a negotiated SLA.
Built for regulated industries worldwide
Banks, payment processors, and fintechs securing payment APIs, fraud detection AI agents, and transaction processing systems.
Hospitals, health tech, and pharma companies protecting patient data APIs, medical AI assistants, and HIPAA-compliant systems.
Federal agencies and contractors securing classified systems, citizen services APIs, and government AI applications.
Deep dive into G8KEPR enterprise architecture and security controls.
Read Article →How to achieve and maintain SOC 2 alignment with G8KEPR.
Read Article →Cloud, on-premise, and hybrid deployment architectures explained.
Read Article →Schedule a demo with our team to discuss your security requirements, compliance needs, and custom deployment options.