Your operation. Your data.
Your rules.
Before an agent touches a customer, three questions need an answer: who owns what it learns, where it runs, and what stops it making a move your policy doesn't allow. Here are ours.
You own what it says. We own the language it's written in.
Everything that describes how your business runs is yours — contractually, in your tenant, from day one. What we own is the layer underneath, and it gets better for every client.
Your rulebook.
Every entity, threshold, policy and captured decision. Held in your tenant and exportable in open formats.
The platform underneath.
The canonical model, the industry ontology, the lifecycle patterns and state machines your rulebook is written in.
Everything built for you is yours from day one. The platform can be too.
In our cloud, in yours — or yours to keep.
You choose where the platform runs and who operates it. The rulebook, the enforcement and the record are the same every way.
We run it for you.
On Google Cloud or AWS. We operate the environment; your rulebook and data stay yours, and exportable.
Inside your firewall.
On AWS, Azure or Google Cloud — fully air-gapped if you need it. Your team operates it, or ours does.
Keep it and run it as your own.
After implementation, the platform can be yours for good. Your team operates it, or we do.
Yours to keep is a perpetual licence, priced in your contract.
An action your policy forbids isn't discouraged. It's impossible.
A prompt asks a model to behave. A rule doesn't ask. Authority limits, thresholds and exceptions live as structure the system enforces — on every automated path, not only the ones someone thought to test.
Anything above a limit goes to a named person, with the context attached. Every action and every decision is recorded: who, what, when, and why.
Invented case. No client data.
Certified, filed, and incorporated.
Found a vulnerability? Tell us first.
We run AI in live operations, and we want independent researchers testing it. Good-faith research is welcome here, and reported issues get a fast, direct response.
- Prompt injection and jailbreaks
- Data leakage or unauthorized access
- Authentication and authorization bypass
- API and tool-calling vulnerabilities
- Context manipulation
- Social engineering of our people
- Physical security
- Denial-of-service testing
- Third-party services — report to them directly
- Theoretical issues without a proof of concept
- No legal action against good-faith research
- Acknowledging your report within two business days
- Keeping you informed until it's fixed
- Public credit, if you want it
- Report privately first
- Go no further than a proof of concept — no access to or changes in real data
- Don't disrupt live services
- Allow 45 days for a fix before public disclosure
To report: email engage@cygnusalpha.one with [SECURITY] in the subject. Include what you found, the steps to reproduce it, the impact as you see it, and how you'd like to be credited.
Running a security review on your side? Start with a conversation.
The first conversation is thirty minutes about fit — not a demo, not an audit. Tell us early what your review needs, and we'll sequence around it.
30 minutes. A conversation about fit. References available on request.