Security, privacy, and responsible AI

Security and privacy in the private beta.

How the private beta handles identity, authorization, encryption, monitoring, data retention, incident response, and AI use.

Control inventory

What’s active now, and what’s planned.

Every control below is marked active or planned.

Identity

Entra ID authentication

OIDC sign-in, identity-provider MFA, and role claims protect workforce and tenant access to the control plane.

Active
Authorization

Tenant-scoped RBAC

Workspace roles and server-side tenant checks constrain configuration, routing, audit export, and privileged administration.

Active
Secrets

Managed identities and Key Vault

Azure managed identities replace embedded service credentials; secrets and certificates are stored in Key Vault and access is logged.

Active
Encryption

Protected in transit and at rest

TLS protects public and service connections. Azure-managed encryption protects Cosmos DB, Blob Storage, and Service Bus data at rest.

Active
Isolation

Tenant-aware data boundaries

Tenant identifiers, partition keys, authorization checks, and scoped audit exports separate each workspace in the shared service.

Active
Edge protection

WAF, quotas, and rate limits

Front Door WAF policies and API Management limits protect the public API boundary from malformed, abusive, or unbounded requests.

Active
Detection

Central operational telemetry

Application Insights and Log Analytics collect authentication, policy, latency, failure, and administrative events with alert routing.

Active
Authority and budget

Bounded agent authority

Every transaction carries a scope, an expiration, and a spend ceiling. Sensitive routes can require a second authorization before work leaves the boundary.

Active
Policy termination

Pre-egress enforcement

Policy-as-code rules are evaluated before anything crosses the boundary, and every allow or deny decision is recorded with the transaction.

Active
Evidence minimization

Proof without raw data

Receipts carry hashes, pointers, and bounded disclosures instead of raw artifacts by default, with redaction and short-retention options per workspace.

Active
Value boundary

No custody of customer funds

Value stays in accounts the customer controls. Where a budget rule requires co-authorization, the policy engine holds an additional key and can never move value alone.

Active
Recovery

Secondary-region runbook

A warm recovery environment, replicated configuration, documented objectives, and rehearsed regional failover remain future work.

Planned
Premium isolation

Dedicated tenant accounts

Separate data accounts and throughput boundaries for customers with stronger isolation requirements remain on the roadmap.

Planned

Data handling

What we store, why, and for how long.

The gateway persists configuration and operational metadata while treating routed payload content as transient by default.

Data classHandlingRetention
Account and tenant recordsUsed for authentication, role assignment, workspace ownership, and support.Account life plus 30 days.
Endpoint and policy configurationStored in tenant partitions; sensitive connector values reference Key Vault secrets.Until deletion plus a 30-day recovery window.
Transaction metadata and receiptsThe transaction ID, route, timing, outcome class, policy decision, and receipt reference are retained for each transaction; the payload itself is not.30 days standard, configurable to 7 days.
Customer payload contentProcessed in memory for authorized routing and not used to train a shared model.Not persisted by default.
Audit export packagesEncrypted customer-requested packages stored with tenant-scoped access.90 days, then lifecycle deletion.
Security telemetryAuthentication, administrative, error, and alert events used to detect and investigate misuse.90 days in the private beta.

AI-use boundary

Your team stays in charge of every AI decision.

CGP Gateway may route a customer-authorized request to an AI service or agent. The product does not train a shared foundation model from customer payloads and does not independently approve high-impact outcomes.

Customers choose destinations, configure route policies, validate outputs, and remain responsible for lawful and appropriate use of connected systems.

Destination choice

Customer authorized

Only endpoints registered and allowed by the workspace policy can receive a routed request.

Model training

No shared training use

Routed payloads are not used to train a common model or build advertising profiles.

Decision boundary

No autonomous high-impact approval

The gateway does not make legal, financial, employment, medical, safety-critical, or eligibility decisions.

Human oversight

Configured by operators

Customer teams define policies, test routes, inspect events, and decide how downstream AI outputs may be used. Consent stays with the principal.

Attribution

Delegated or autonomous

Audit records distinguish actions a person delegated from actions an agent took on its own initiative.

Incident readiness

How we detect, contain, and recover.

The Chief Cloud and Security Officer coordinates triage, engineering containment, evidence preservation, and recovery, plus customer communication when it's required.

Internal response targets support private-beta operations; they are not a public service-level agreement.

01 · Detect

Alert and classify

Centralized alerts and reports enter a severity matrix; critical alerts are acknowledged within a 30-minute target.

02 · Contain

Limit access and impact

Operators can revoke identities, rotate secrets, block routes, isolate revisions, and preserve relevant audit evidence.

03 · Recover and learn

Restore and review

Runbooks guide validated restoration, post-incident review, corrective actions, and notification where law or contract requires it.

Backups: daily configuration backups, lifecycle-managed encrypted artifacts, and quarterly restore tests are in place. Multi-region recovery and a formally tested regional failover are planned.

Independent assurance

Where we stand on certifications.

IOAI Gateway, Inc. does not currently hold a SOC 2 report, ISO/IEC 27001 certification, PCI DSS attestation, HIPAA assessment, or FedRAMP authorization.

A readiness assessment, control-evidence program, penetration test, and vendor-risk process are planned before any public assurance statement.

Current

Documented beta controls

Policies, implementation records, vulnerability scans, restore tests, and incident exercises are documented internally.

Planned

External validation

An independent penetration test and SOC 2 readiness review will precede any public assurance claim.

Commitment

Precise status only

We publish certification status only when dated evidence supports it.

Security contact

Report a vulnerability.

Use the Contact page and select the security inquiry type, or email us directly using the address below.

Open contact