Entra ID authentication
OIDC sign-in, identity-provider MFA, and role claims protect workforce and tenant access to the control plane.
ActiveSecurity, privacy, and responsible AI
How the private beta handles identity, authorization, encryption, monitoring, data retention, incident response, and AI use.
Control inventory
Every control below is marked active or planned.
OIDC sign-in, identity-provider MFA, and role claims protect workforce and tenant access to the control plane.
ActiveWorkspace roles and server-side tenant checks constrain configuration, routing, audit export, and privileged administration.
ActiveAzure managed identities replace embedded service credentials; secrets and certificates are stored in Key Vault and access is logged.
ActiveTLS protects public and service connections. Azure-managed encryption protects Cosmos DB, Blob Storage, and Service Bus data at rest.
ActiveTenant identifiers, partition keys, authorization checks, and scoped audit exports separate each workspace in the shared service.
ActiveFront Door WAF policies and API Management limits protect the public API boundary from malformed, abusive, or unbounded requests.
ActiveApplication Insights and Log Analytics collect authentication, policy, latency, failure, and administrative events with alert routing.
ActiveEvery transaction carries a scope, an expiration, and a spend ceiling. Sensitive routes can require a second authorization before work leaves the boundary.
ActivePolicy-as-code rules are evaluated before anything crosses the boundary, and every allow or deny decision is recorded with the transaction.
ActiveReceipts carry hashes, pointers, and bounded disclosures instead of raw artifacts by default, with redaction and short-retention options per workspace.
ActiveValue stays in accounts the customer controls. Where a budget rule requires co-authorization, the policy engine holds an additional key and can never move value alone.
ActiveA warm recovery environment, replicated configuration, documented objectives, and rehearsed regional failover remain future work.
PlannedSeparate data accounts and throughput boundaries for customers with stronger isolation requirements remain on the roadmap.
PlannedData handling
The gateway persists configuration and operational metadata while treating routed payload content as transient by default.
| Data class | Handling | Retention |
|---|---|---|
| Account and tenant records | Used for authentication, role assignment, workspace ownership, and support. | Account life plus 30 days. |
| Endpoint and policy configuration | Stored in tenant partitions; sensitive connector values reference Key Vault secrets. | Until deletion plus a 30-day recovery window. |
| Transaction metadata and receipts | The transaction ID, route, timing, outcome class, policy decision, and receipt reference are retained for each transaction; the payload itself is not. | 30 days standard, configurable to 7 days. |
| Customer payload content | Processed in memory for authorized routing and not used to train a shared model. | Not persisted by default. |
| Audit export packages | Encrypted customer-requested packages stored with tenant-scoped access. | 90 days, then lifecycle deletion. |
| Security telemetry | Authentication, administrative, error, and alert events used to detect and investigate misuse. | 90 days in the private beta. |
AI-use boundary
CGP Gateway may route a customer-authorized request to an AI service or agent. The product does not train a shared foundation model from customer payloads and does not independently approve high-impact outcomes.
Customers choose destinations, configure route policies, validate outputs, and remain responsible for lawful and appropriate use of connected systems.
Only endpoints registered and allowed by the workspace policy can receive a routed request.
Routed payloads are not used to train a common model or build advertising profiles.
The gateway does not make legal, financial, employment, medical, safety-critical, or eligibility decisions.
Customer teams define policies, test routes, inspect events, and decide how downstream AI outputs may be used. Consent stays with the principal.
Audit records distinguish actions a person delegated from actions an agent took on its own initiative.
Incident readiness
The Chief Cloud and Security Officer coordinates triage, engineering containment, evidence preservation, and recovery, plus customer communication when it's required.
Internal response targets support private-beta operations; they are not a public service-level agreement.
Centralized alerts and reports enter a severity matrix; critical alerts are acknowledged within a 30-minute target.
Operators can revoke identities, rotate secrets, block routes, isolate revisions, and preserve relevant audit evidence.
Runbooks guide validated restoration, post-incident review, corrective actions, and notification where law or contract requires it.
Backups: daily configuration backups, lifecycle-managed encrypted artifacts, and quarterly restore tests are in place. Multi-region recovery and a formally tested regional failover are planned.
Independent assurance
IOAI Gateway, Inc. does not currently hold a SOC 2 report, ISO/IEC 27001 certification, PCI DSS attestation, HIPAA assessment, or FedRAMP authorization.
A readiness assessment, control-evidence program, penetration test, and vendor-risk process are planned before any public assurance statement.
Policies, implementation records, vulnerability scans, restore tests, and incident exercises are documented internally.
An independent penetration test and SOC 2 readiness review will precede any public assurance claim.
We publish certification status only when dated evidence supports it.
Security contact
Use the Contact page and select the security inquiry type, or email us directly using the address below.