AnantState
Trust and security

What we enforce, what we attest, and what we do not claim.

Security pages usually list only the good news. This one separates the three categories, because a reviewer needs to know which is which.

1 · What the platform enforces

Capabilities in the shipped product, demonstrable in a live system.

ControlHow it is enforced
Tenant isolationRow-level security in the database, not application-level filtering
Role-based accessRole and workspace evaluated on every request
Single sign-onOIDC
Multi-factor authenticationMFA challenge at login
Directory provisioningSCIM
Action attributionEvery action recorded against the acting user
Tenant-scoped audit trailActions queryable per tenant
Policy, rule and limit governanceVersioned objects, not free text
Budget and notification limitsEnforced by the platform
Model promotion gateRefuses on provenance, divergence, null-baseline and unmeasured-horizon checks
Override attributionHuman overrides of a gate refusal are logged with actor and reason
Edition gatingThe demo simulator exists only in the demo edition

Why tenancy belongs at the database layer. If isolation is enforced in application code, one missed filter (one query, one new endpoint, one refactor) is a cross-tenant leak. Moving the control into the database means the application’s failure mode is closed rather than open. It is the single most important architectural security decision in the product.

2 · Data posture

QuestionAnswer
What access do you need to our systems?Read-mostly by default: events and reference data.
Can you write into our systems?Only through explicit, named, audited actions.
Is there a background write path?No.
What happens to events that fail to map?They land in a dead-letter view with the reason. Nothing is silently dropped.
Do you become our system of record?No. Your warehouse stays yours.
Can it run in a segmented network?Yes. The read-mostly posture is why plant and operational-technology deployments are viable.
Can another customer’s data reach ours?No. There is no cross-tenant path of any kind. See cross-domain.

Answers to what reviewers ask first

QuestionAnswer
Where does it run?In infrastructure you control: single-host containers, Kubernetes, or your cloud account with a managed database. See deployment.
Where does our data live?Where you put it. There is no shared hosted estate.
How is tenant isolation enforced?By the database, not the application. An application defect cannot widen visibility.
How do users authenticate?Single sign-on over OIDC, directory provisioning over SCIM, multi-factor authentication at login.
What can it write to our systems?Nothing by default. Any write is a named, audited action.
How do events get in?Streams, REST sources, scheduled pulls or bulk import. Failures are held in a dead-letter view. See event-driven.
Can a model reach production unvalidated?Not by default. The promotion gate refuses and records why. An override is attributed.
Is there an audit trail?Every action is recorded with the acting user, scoped to the tenant.
Can another customer’s data reach ours?No cross-tenant path exists.
Where is the security documentation?We walk reviewers through it in a conversation and answer the questionnaire directly.

3 · What this page does not claim

This section is the point of the page.

A security reviewer should see the gaps in the same detail as the controls. If a claim is not in section 1, it is not claimed. For each item below, this page makes no statement either way. Ask us, and we will give you the current position in writing.

ItemPosition on this page
SOC 2 and ISO 27001Not claimed. Ask for current status.
Penetration test reportNot claimed. Ask for the most recent date and scope.
Data residency optionsDeployment is into infrastructure you control. No hosted region list is published.
Data processing agreement and sub-processor listNot published here. Ask for the current documents.
Accessibility conformance statementNot claimed.
Regulatory mapping (financial, health, public sector)Not claimed. We state controls; your compliance function maps them.
Whether customer data trains models used by other tenantsNo cross-tenant path exists in the platform (section 2). The contractual position is available on request.
Model and data ownership termsA contractual matter. Ask for the current position.

The audit trail, in the product

Every blocked and held action is recorded with its reason.

The audit log: a compliance snapshot and the guard rails that blocked actions, including entities whose conflicting evidence holds autonomous actionFictional reference world: OgMart
Every blocked and held action is recorded with its reason, including actions held because the evidence conflicts.

Put your security reviewer in the room

Bring the questionnaire. A conversation is faster than a document, and the answer comes with the person who can demonstrate it.