Controls you can check today.
Compliance is a long road, and we'll tell you exactly where we are on it. But you don't have to wait for a framework letter to verify how a run behaved — the runtime produces signed evidence you re-check yourself, on your own machine, right now.
The honest status.
No badges we haven't earned. Here's each framework, stated plainly — what's done, what's targeted, and what to read it as.
SOC 2 Type II
Targeted for Q3 2026 — not yet attested. There is no SOC 2 report today, and we won't imply there is one. When an independent auditor completes the examination, we'll publish it here and link the report. Until then, treat SOC 2 as planned, not held.
STATUS · TARGETED Q3 2026CMMC
Self-assessed alignment — a documented internal review of our practices against the CMMC control set. This is our own assessment, not a third-party certification. We share the supporting evidence on request so you can judge it for yourself.
STATUS · SELF-ASSESSEDNIST 800-171
Controls mapped. We've mapped Halo's runtime behavior to the relevant 800-171 controls, so the evidence the runtime emits lines up with what an assessor looks for. Mapping is the starting point for an assessment — not a claim of certification.
STATUS · CONTROLS MAPPEDOSCAL / eMASS export
On the Business tier, Halo emits machine-readable OSCAL and eMASS-shaped exports built from the signed audit chain — so your GRC team and assessors get re-verifiable evidence in the formats they already work in, not a PDF to take on faith.
BUSINESS · RE-VERIFIABLEWhat an auditor checks first — and what Halo produces.
Most controls come down to a few recurring questions. For each one, here's the evidence the runtime emits — so the answer is something you can inspect, not something we narrate.
Immutable, append-only logging AU · AUDIT
The first thing an assessor wants is a record that can't be quietly edited after the fact. Every action — prompt, tool call, output, routing decision, kill — is Ed25519-signed and hash-chained into the audit log. Change one byte anywhere in the chain and re-verification fails. The evidence is the log itself, not a description of it.
Least-privilege egress AC · BOUNDARY
Auditors look for hard boundaries, not policy promises. Each run executes in a no-route sandbox with no path to the internet, and a single sole-egress broker is the only process that can reach a provider — policy-checked for known model, budget cap and kill-switch on every call. The containment is structural; there's nothing for an agent to "get around."
Continuous monitoring & actor attribution CA · ACCOUNTABILITY
Who did what, and under whose authority. On Team and above, every action across the org lands in one actor-stamped signed chain, with RBAC and separation of duties enforced at the broker. The result is a continuous, attributable record of runs and approvals — captured as evidence, drawn straight from how the runtime actually operated.
Key & secret handling SC · KEYS
Provider keys live in a per-tenant encrypted vault, never enter the agent container, and are never logged. The broker uses a key for exactly one call, then it's gone. So the answer to "where do the secrets live and who can see them" is a bounded, evidenced one — not a paragraph in a policy binder.
The point isn’t to ask you to trust us. It’s that you can re-verify offline — export the run, check every signature on your own machine, and take our word for nothing.
Found something? Tell us.
We welcome responsible disclosure. If you believe you've found a vulnerability, email security@perimeterone.ai with the details and steps to reproduce. We'll acknowledge your report and keep you posted as we work it.
Verify it yourself.
Run a real agent behind the broker, export the run, and re-check every signature offline — no badge required, no trust extended. Solo $29 · Team $544 · Business $1,779.