Security & Trust

Automation you can
prove is safe.

Saltstone agents work inside your most sensitive processes, so security and auditability are part of the platform—not an add-on.

Request a security review
Saltstone security shield

Secure by design

Security is embedded into every agent, integration, and workflow from the first line of code.

Observable by default

Every action is logged, traceable, and reviewable so you can prove what happened and why.

Least privilege

Agents receive only the scoped permissions they need for the task at hand—nothing more.

Security controls

How we protect your data

A layered security model built for agent-driven automation in regulated industries.

Encryption everywhere

Data is encrypted in transit and at rest across every environment we operate, with keys managed through strict access controls.

Least-privilege access

Agents connect through scoped credentials with role-based access, segregation of duties, and just-in-time permissions.

Full decision lineage

Every agent action records its inputs, reasoning, outputs, and human checkpoints for complete auditability.

Data minimization

We process only the fields a workflow requires, with configurable retention windows and safe deletion policies.

Resilient operations

Monitored pipelines, graceful failover, circuit breakers, and human escalation paths protect every workflow.

Compliance alignment

Controls are designed for regulated environments, including healthcare, financial services, and data-protection frameworks.

256-bit

Encryption at rest

TLS 1.3

Data in transit

SOC 2

Aligned controls

99.99%

Target availability

Need our security documentation?

We'll share our control overview and answer every question your review team has.

Contact us