GovernorAI is built with a trust-by-design approach. Zero-trust architecture, deterministic enforcement, and provable audit trails are foundational, not features.
No agent has implicit access to any system. Every action is verified against policy. No exceptions.
If policy evaluation fails, if the gateway is unreachable, or if no policy matches—the action is denied. Always.
GovernorAI's policy engine is purely deterministic. YAML + OPA/Rego. No probabilistic decisions. No model drift in the governance layer.
What we log. What we don't. How we protect it.
Structured governance events: agent ID, session ID, tool name, policy decision, timestamp, latency. Designed for compliance auditing.
No raw prompts. No model outputs. No customer PII in governance logs. GovernorAI logs governance decisions, not conversation content.
Self-hosted deployments keep all data in your environment. SaaS deployments support region selection for data residency requirements.
AES-256 encryption at rest. TLS 1.3 in transit. mTLS between all internal components. No unencrypted data paths.
GovernorAI provides controls aligned with major compliance frameworks.
Immutable audit trails, access controls, change management, and monitoring controls aligned with SOC 2 Trust Services Criteria.
Data minimization, purpose limitation, audit logging, and data residency controls aligned with GDPR requirements.
Access governance, audit trails, and administrative safeguards aligned with HIPAA security requirements for AI handling PHI.
Transparency, human oversight, risk management, and technical documentation controls for high-risk AI systems.
Your security requirements determine your deployment model.
Managed GovernorAI infrastructure. We handle operations, scaling, and updates. You configure policies and govern your agents.
Deploy GovernorAI entirely in your infrastructure. No data leaves your environment. Full operational control.
Full GovernorAI functionality with zero external network dependencies. For environments where internet access is not an option.
OAuth2/OIDC for authentication. RBAC for authorization. Integration with your existing identity provider. No shared secrets.
mTLS between all components. Certificate rotation. VPC peering for self-hosted deployments. No plaintext communication.
SentinelLayer takes security incidents seriously. Our incident response process includes:
To report a security issue, contact security@sentinellayer.dev.
SentinelLayer has filed patent applications covering key aspects of our governance architecture, including:
This IP supports platform defensibility while we build an open, integration-first governance layer. SentinelLayer™ and GovernorAI™ are trademarks of SentinelLayer, Inc.
We're happy to discuss our security practices, deployment options, and compliance alignment in detail.