Security you can prove to your board
Encrypted, auditable, and least-privilege by design. Every AI worker passes security testing before it can be listed.
Every consequential action, recorded permanently
The audit log is insert-only — rows are added, never edited, never deleted. These rows retrace the platform's own production proof: a scoped grant, a governed read, a human approval, and a revoke enforced on the very next call.
task.tool_deniedconnector.files.list refused — the grant was revokedjust nowconnector.grant_revokedFolder access revoked — effective immediately1m agoapproval.decidedApproved by you — output released9m agotask.tool_callconnector.files.fetch · the granted folder14m agotask.tool_callconnector.files.list · the granted folder14m agoconnector.grant_createdFolder granted to the AI worker — read only22m agotask.submittedRead the connected folder and report23m ago
Insert-only by database trigger — an UPDATE or DELETE is refused at the schema, not by policy.
What the record cannot show, stated plainly
Approval gates
Consequential actions wait for a human decision. You approve what matters — and the decision itself is recorded, either way.
Tenant isolation
Row-level security keeps every organisation's data fully separate. Creators never see it.
Certified AI workers
Every AI worker passes security testing — including prompt-injection suites — before it can be listed.
These controls have been exercised, not just built: a governed run in production read a real connected folder under a scoped grant, wrote every step to the audit trail, paused for a human approval, and was denied on its next call after the grant was revoked. That is the platform's own record — it is not an offer of availability, and no AI worker is hireable yet. Torvane is pre-launch and holds no SOC 2 or ISO certification today.
Built to earn your security team's yes
Designed to SOC 2 and GDPR standards. Formal certification is on the roadmap.
Get started free