Trust & Security

Your operation. Your data.
Your rules.

Before an agent touches a customer, three questions need an answer: who owns what it learns, where it runs, and what stops it making a move your policy doesn't allow. Here are ours.

You own what it says. We own the language it's written in.

Everything that describes how your business runs is yours — contractually, in your tenant, from day one. What we own is the layer underneath, and it gets better for every client.

Yours

Your rulebook.

Every entity, threshold, policy and captured decision. Held in your tenant and exportable in open formats.

Ours · improved for everyone

The platform underneath.

The canonical model, the industry ontology, the lifecycle patterns and state machines your rulebook is written in.

Everything built for you is yours from day one. The platform can be too.

In our cloud, in yours — or yours to keep.

You choose where the platform runs and who operates it. The rulebook, the enforcement and the record are the same every way.

Hosted

We run it for you.

On Google Cloud or AWS. We operate the environment; your rulebook and data stay yours, and exportable.

Your cloud

Inside your firewall.

On AWS, Azure or Google Cloud — fully air-gapped if you need it. Your team operates it, or ours does.

Yours to keep

Keep it and run it as your own.

After implementation, the platform can be yours for good. Your team operates it, or we do.

Yours to keep is a perpetual licence, priced in your contract.

An action your policy forbids isn't discouraged. It's impossible.

A prompt asks a model to behave. A rule doesn't ask. Authority limits, thresholds and exceptions live as structure the system enforces — on every automated path, not only the ones someone thought to test.

Anything above a limit goes to a named person, with the context attached. Every action and every decision is recorded: who, what, when, and why.

One refund · illustrative
09:41REFUND RF-2208 · damaged item · $640
09:41above the $500 agent limit · refused, logged
09:42→ supervisor · order, photos, history attached
09:58J. Alvarez, supervisor · approved · reason recorded
09:59refund issued · customer told · record complete

Invented case. No client data.

Certified, filed, and incorporated.

ISO 27001
Information security · 2022 standard · certified
ISO 9001
Quality management · certified
2
Provisional patents filed
Delaware
C-Corporation

Found a vulnerability? Tell us first.

We run AI in live operations, and we want independent researchers testing it. Good-faith research is welcome here, and reported issues get a fast, direct response.

In scope
  • Prompt injection and jailbreaks
  • Data leakage or unauthorized access
  • Authentication and authorization bypass
  • API and tool-calling vulnerabilities
  • Context manipulation
Out of scope
  • Social engineering of our people
  • Physical security
  • Denial-of-service testing
  • Third-party services — report to them directly
  • Theoretical issues without a proof of concept
We commit to
  • No legal action against good-faith research
  • Acknowledging your report within two business days
  • Keeping you informed until it's fixed
  • Public credit, if you want it
We ask that you
  • Report privately first
  • Go no further than a proof of concept — no access to or changes in real data
  • Don't disrupt live services
  • Allow 45 days for a fix before public disclosure

To report: email engage@cygnusalpha.one with [SECURITY] in the subject. Include what you found, the steps to reproduce it, the impact as you see it, and how you'd like to be credited.

Running a security review on your side? Start with a conversation.

The first conversation is thirty minutes about fit — not a demo, not an audit. Tell us early what your review needs, and we'll sequence around it.

30 minutes. A conversation about fit. References available on request.