Trust & Compliance

Controls you can check today.

Compliance is a long road, and we'll tell you exactly where we are on it. But you don't have to wait for a framework letter to verify how a run behaved — the runtime produces signed evidence you re-check yourself, on your own machine, right now.

Where we stand

The honest status.

No badges we haven't earned. Here's each framework, stated plainly — what's done, what's targeted, and what to read it as.

SOC 2 Type II

Targeted for Q3 2026 — not yet attested. There is no SOC 2 report today, and we won't imply there is one. When an independent auditor completes the examination, we'll publish it here and link the report. Until then, treat SOC 2 as planned, not held.

STATUS · TARGETED Q3 2026

CMMC

Self-assessed alignment — a documented internal review of our practices against the CMMC control set. This is our own assessment, not a third-party certification. We share the supporting evidence on request so you can judge it for yourself.

STATUS · SELF-ASSESSED

NIST 800-171

Controls mapped. We've mapped Halo's runtime behavior to the relevant 800-171 controls, so the evidence the runtime emits lines up with what an assessor looks for. Mapping is the starting point for an assessment — not a claim of certification.

STATUS · CONTROLS MAPPED

OSCAL / eMASS export

On the Business tier, Halo emits machine-readable OSCAL and eMASS-shaped exports built from the signed audit chain — so your GRC team and assessors get re-verifiable evidence in the formats they already work in, not a PDF to take on faith.

BUSINESS · RE-VERIFIABLE
Evidence, not assertions

What an auditor checks first — and what Halo produces.

Most controls come down to a few recurring questions. For each one, here's the evidence the runtime emits — so the answer is something you can inspect, not something we narrate.

01

Immutable, append-only logging AU · AUDIT

The first thing an assessor wants is a record that can't be quietly edited after the fact. Every action — prompt, tool call, output, routing decision, kill — is Ed25519-signed and hash-chained into the audit log. Change one byte anywhere in the chain and re-verification fails. The evidence is the log itself, not a description of it.

02

Least-privilege egress AC · BOUNDARY

Auditors look for hard boundaries, not policy promises. Each run executes in a no-route sandbox with no path to the internet, and a single sole-egress broker is the only process that can reach a provider — policy-checked for known model, budget cap and kill-switch on every call. The containment is structural; there's nothing for an agent to "get around."

03

Continuous monitoring & actor attribution CA · ACCOUNTABILITY

Who did what, and under whose authority. On Team and above, every action across the org lands in one actor-stamped signed chain, with RBAC and separation of duties enforced at the broker. The result is a continuous, attributable record of runs and approvals — captured as evidence, drawn straight from how the runtime actually operated.

04

Key & secret handling SC · KEYS

Provider keys live in a per-tenant encrypted vault, never enter the agent container, and are never logged. The broker uses a key for exactly one call, then it's gone. So the answer to "where do the secrets live and who can see them" is a bounded, evidenced one — not a paragraph in a policy binder.

The point isn’t to ask you to trust us. It’s that you can re-verify offline — export the run, check every signature on your own machine, and take our word for nothing.
— How we think about evidence
Security contact

Found something? Tell us.

We welcome responsible disclosure. If you believe you've found a vulnerability, email security@perimeterone.ai with the details and steps to reproduce. We'll acknowledge your report and keep you posted as we work it.

Verify it yourself.

Run a real agent behind the broker, export the run, and re-check every signature offline — no badge required, no trust extended. Solo $29 · Team $544 · Business $1,779.