Skip to main content
SOC 2 Type II Observation In Progress • 12 Compliance Frameworks Mapped

Enterprise AI Security
At Scale, With Confidence

The AI Security Layer for enterprise: API security, MCP security, AI gateway, and verification engine — unified under one correlation ID with tamper-evident hash-chain audit, Patroni HA and Helm charts for customer-hosted deployments, and 12 compliance frameworks with automated assessment (plus 8 reference catalogs). All 4 pillars, custom-quoted (Contact Sales — priced to your scale and compliance needs).

SOC 2 Type II — In Progress (external audit engagement H2 2026)
HIPAA-Ready
PCI-DSS Ready
1-hour P1 response (Enterprise SLA)
12
assessment frameworks (+8 reference)
7-year
audit retention (84-month WORM)
SHA-256
hash-chain audit (CC7.2 / §164.312(b))
Patroni
HA compose ships (customer-hosted)
4-dim
Zero Trust composite risk score
Helm
charts + an AWS Terraform starting point
104
workflow files (hosted CI paused; gates run locally)
99.9%
Uptime target · 1-hr P1 (Enterprise)

Enterprise-Grade Security

Built for regulated industries with compliance, scale, and security at the core

Automated Compliance

Auto-generated SOC 2, HIPAA, and PCI evidence packages. A published control crosswalk maps each SOC 2 control to its overlapping ISO 27001 and HIPAA controls.

  • Quarterly compliance reports
  • Audit trail export (CSV, JSON)
  • Evidence logs for auditors

Multi-Tenancy

SSO/SAML sign-in is not yet available. Multi-tenant administration with organization-level isolation and SAML XML Signature Wrapping (XSW) defense.

  • OIDC/JWKS authentication
  • Role-based access control
  • Organization isolation

Custom Deployment

Cloud, on-premise, or air-gapped deployment. Deploy in the region you choose for data residency, with a dedicated VPC, private endpoints, and high availability from the shipped Helm charts and Patroni PostgreSQL.

  • Private cloud deployment
  • Architecture supports air-gapped deployment
  • Customer-hosted HA (Helm, Patroni)

Complete AI Security Platform

Enterprise plans include unlimited access to all 4 pillars of the G8KEPR platform

API Security

Unlimited Requests
  • Unlimited API requests tracked
  • WAF (Web Application Firewall)
  • mTLS to upstream services
  • Advanced rate limiting & circuit breakers

MCP Security

Unlimited Tool Calls
  • Unlimited MCP tool calls
  • Enterprise permission framework
  • Custom security policies per agent
  • Multi-agent orchestration monitoring

AI Gateway

Unlimited LLM Providers
  • Unlimited LLM providers (BYOK)
  • Enterprise cost tracking & chargebacks
  • Custom routing strategies
  • Private model endpoints

Verification Engine

4 Validation Layers
  • Constraint enforcement (forbidden phrases, format, length, PII)
  • Source grounding (citation verification, hallucination detection)
  • Structural validation (JSON schema, regex, expected structure)
  • BLOCK-capable enforcement on selected critical paths

12 Compliance Frameworks, One Audit Log

Every state-changing operation is appended to a SHA-256 hash-chained audit log. Control crosswalk: each SOC 2 control is mapped to its overlapping ISO 27001 and HIPAA controls.

EU AI Act
Articles 9, 11, 12, 13, 14, 15
controls implemented
SOC 2 Type II
CC6.1 / CC6.6 / CC7.2 / A1 / C1
observation in progress
HIPAA
Security Rule §164 + 7-yr audit + BAA
-Ready (BAA available)
GDPR
Articles 5, 12, 17, 28, 32 + DPA
controls implemented
PCI DSS v4.0
55 controls across 12 requirements
-Ready
ISO 27001:2022
93 Annex A controls
aligned (not certified)
FedRAMP
84 controls · NIST 800-53 mapping · 3 baselines
AU-9 evidence available
CMMC 2.0
110+ practices · DoD-ready
evidence aggregation
NIST CSF 2.0
106 subcategories · function-level mapping
mapped
NIST 800-53 Rev 5
115 controls in the assessment engine
control implementation checks
GDPR DPA
Article 28 · subprocessor tracking
DPA generation workflow
Control Crosswalk
control_mappings.py
published mappings, manual status propagation

"-Ready" / "aligned" / "controls implemented" reflect capability posture. SOC 2 Type II, HIPAA, ISO 27001 certifications pending external audit. Audit retention: 90 days hot (PostgreSQL monthly partitions), 7 years cold (S3 WORM Object Lock COMPLIANCE mode).

Service Level Commitments

Aligned with the Starter / Pro / Enterprise tiers on our pricing page. Contractual SLA ships with the Master Service Agreement.

Starter
Best effort
availability target
Community support
Monthly downtime budget: No SLA guarantee
★ Recommended
Pro
99.9%
availability target
Priority email support
Monthly downtime budget: ~43 min/mo
Enterprise
Custom
availability target
Dedicated support
Monthly downtime budget: Per MSA

Production-Grade Operations Out of the Box

Patroni HA and Helm charts ship for customer-hosted deployments. Kubernetes-native. No DIY required.

High Availability

For customer-hosted deployments: PostgreSQL with Patroni + etcd + HAProxy quorum-based failover (a 2026-09-18 drill measured 31.7 s to the next acknowledged write, with 0 of 1,028 acknowledged writes lost), uvicorn workers with process-level isolation, and Nginx upstream health checks. The hosted service runs on a single node without them.

Helm and Terraform

Helm charts for the platform, the collector and the sensors, and an AWS Terraform module (VPC, RDS, ElastiCache, KMS, Secrets Manager) ship for customer-hosted installs. The module provisions the infrastructure; installing the platform onto it is the separate Helm step.

104 Workflow Files

CodeQL, Trivy container scanning, Bandit, pip-audit + npm audit, OWASP ZAP, Gitleaks, Semgrep SAST and Lighthouse are all defined in the repository. Hosted CI is paused for cost, so 10 workflows are active and the rest are disabled with a dated reason in docs/ci/04-workflow-dispositions.md; the gates, including the held-out detection test, are run locally.

Zero Trust Risk Scoring

4-dimension composite score (device 25% / location 25% / behavior 30% / time 20%), computed and recorded on every login, with impossible-travel detection via Haversine. Elevated scores are logged for review; the allow / monitor / step-up / deny bands are reported, not yet enforced on the login or request path.

Helm + Kubernetes

Six Helm manifests: Deployment with rolling updates, HorizontalPodAutoscaler, PodDisruptionBudget, NetworkPolicy, ExternalSecrets, PrometheusRule. SHA-pinned images, non-root containers, defined HEALTHCHECK.

Tamper-Evident Audit

SHA-256 hash chain with all-zeros genesis block. Three verification levels (full / single / last-N). Monthly-partitioned PostgreSQL with 84-month retention. WORM Object Lock COMPLIANCE mode for cold storage.

White-Glove Enterprise Support

Your success is our priority. Get dedicated support from security experts.

Dedicated Support Engineer

Your own engineer who knows your infrastructure inside and out. Available via Slack, email, or phone.

1-Hour P1 (24/7/365)

Pro tier ships a 99.9% availability target with a ~43 minute monthly downtime budget. Enterprise tier negotiates a custom SLA per Master Service Agreement.

Direct Founder Access

Quarterly security reviews with our founding team. Direct Slack channel for strategic guidance and roadmap input.

Enterprise Pricing

Simple, transparent pricing for enterprise teams

Enterprise Plan

Contact Sales

Custom pricing, quoted to your scale, deployment model (VPC, on-prem, or air-gapped), and compliance needs. All 4 pillars, BAA/DPA, and a negotiated SLA.

Unlimited API requests
Full MCP security suite
All LLM providers supported
SOC 2, HIPAA, PCI compliance
Multi-tenancy (SSO not yet available)
1-hour P1 SLA (24/7/365)

Enterprise Use Cases

Built for regulated industries worldwide

Financial Services

Banks, payment processors, and fintechs securing payment APIs, fraud detection AI agents, and transaction processing systems.

Compliance: PCI DSS, SOX, GDPR

Healthcare

Hospitals, health tech, and pharma companies protecting patient data APIs, medical AI assistants, and HIPAA-compliant systems.

Compliance: HIPAA, HITRUST, FDA 21 CFR

Government

Federal agencies and contractors securing classified systems, citizen services APIs, and government AI applications.

Compliance roadmap: FedRAMP (controls mapped), FISMA, NIST 800-53

Ready to Secure Your Enterprise?

Schedule a demo with our team to discuss your security requirements, compliance needs, and custom deployment options.

SOC 2 Type II — In Progress (H2 2026)
99.9% uptime target
1-hour P1 SLA (Enterprise tier)