Trust & Compliance

Controls you can check today.

Compliance is a long road, and we’ll tell you exactly where we are on it. But you don’t have to wait for a framework letter to verify how a run behaved. The runtime produces signed evidence you re-check yourself, on your own machine, right now.

Where we stand

The honest status.

No badges we haven’t earned. Here’s each framework, stated plainly: what’s done, what’s targeted, and what to read it as.

SOC 2 Type II

Targeted for Q3 2026. Not yet attested. There is no SOC 2 report today, and we won’t imply there is one. When an independent auditor completes the examination, we’ll publish it here and link the report. Until then, treat SOC 2 as planned, not held.

STATUS · TARGETED Q3 2026

CMMC

Self-assessed alignment: a documented internal review of our practices against the CMMC control set. This is our own assessment, not a third-party certification. We share the supporting evidence on request so you can judge it for yourself.

STATUS · SELF-ASSESSED

NIST 800-171

Controls mapped. We’ve mapped Halo’s runtime behavior to the relevant 800-171 controls, so the evidence the runtime emits lines up with what an assessor looks for. Mapping is the starting point for an assessment, not a claim of certification.

STATUS · CONTROLS MAPPED

OSCAL / eMASS export

On the Business tier, Halo emits machine-readable OSCAL and eMASS-shaped exports built from the signed audit chain, so your GRC team and assessors get re-verifiable evidence in the formats they already work in, not a PDF to take on faith.

BUSINESS · RE-VERIFIABLE
Evidence, not assertions

What an auditor checks first, and what Halo produces.

Most controls come down to a few recurring questions. For each one, here’s the evidence the runtime emits, so the answer is something you can inspect, not something we narrate.

01

Immutable, append-only logging AU · AUDIT

The first thing an assessor wants is a record that can’t be quietly edited after the fact. Every action (prompt, tool call, output, routing decision, kill) is Ed25519-signed and hash-chained into the audit log. Change one byte anywhere in the chain and re-verification fails. The evidence is the log itself, not a description of it.

02

Least-privilege egress AC · BOUNDARY

Auditors look for hard boundaries, not policy promises. Each run executes in a no-route sandbox with no path to the internet, and a single sole-egress broker is the only process that can reach a provider, policy-checked for known model, budget cap and kill-switch on every call. The containment is structural; there’s nothing for an agent to “get around.”

03

Continuous monitoring & actor attribution CA · ACCOUNTABILITY

Who did what, and under whose authority. On Team and above, every action across the org lands in one actor-stamped signed chain, with RBAC and separation of duties enforced at the broker. The result is a continuous, attributable record of runs and approvals, captured as evidence, drawn straight from how the runtime actually operated.

04

Key & secret handling SC · KEYS

Provider keys live in a per-tenant encrypted vault, never enter the agent container, and are never logged. The broker uses a key for exactly one call, then it’s gone. So the answer to “where do the secrets live and who can see them” is a bounded, evidenced one, not a paragraph in a policy binder.

The point isn’t to ask you to trust us. It’s that you can re-verify offline: export the run, check every signature on your own machine, and take our word for nothing.
How we think about evidence
Security contact

Found something? Tell us.

We welcome responsible disclosure. If you believe you’ve found a vulnerability, email security@perimeterone.ai with the details and steps to reproduce. We’ll acknowledge your report and keep you posted as we work it.

Verify it yourself.

Run a real agent behind the broker, export the run, and re-check every signature offline. No badge required, no trust extended. Solo $29 · Team $129 · Business $449.