SecurityPlatform overview

Clear boundaries for your agents and data.

Understand how Zograph handles access, data, model connections and deployment. Review the controls available to your organization and the responsibilities attached to your configuration.

Cutaway drawing of a pin-tumbler lock cylinder in a wall: its pins, cam and bolt exposed, the key ring in gold, on faint construction lines.

Organization boundaries

Understand the scope of isolation and access.

Data and connections

See where information goes and what controls apply.

Deployment responsibilities

Review the operating model for your configuration.

A practical security overview

Explore the topics on the left, or discuss the requirements of your intended deployment with us.

01Tenant isolation

Access scoped to your organization.

Understand the boundary between organizations, the resources it covers, and the permissions that apply within your own organization.

Organization scope

Review which information and resources belong to each organization.

Permissions within the boundary

Organization membership is distinct from permission to use, configure or inspect a resource.

Organization isolation, workspace permissions and dedicated infrastructure are different properties. Their scope should be assessed separately.

02Identity and access

Access that reflects responsibility.

Review who can use agents, change their configuration, authorize restricted actions and inspect their activity. Authentication and action authority are distinct parts of the access model.

Responsibilities to distinguish

  • Use

    Interact with agents and their permitted capabilities.

  • Configure

    Manage agents, connections and working instructions.

  • Approve

    Provide the authority required for a selected action.

  • Inspect

    Review activity, decisions and execution records.

Review the access model

  • Authentication

    Supported sign-in methods and any deployment-specific identity options.

  • Roles and permissions

    The actual capabilities associated with membership and administrative roles.

  • Membership lifecycle

    How access is granted, changed and removed.

  • Privileged access

    How elevated operational and support access is authorized and controlled.

Requesting is not approving.

Being able to ask an agent to take an action does not, by itself, confer the authority to approve it.

03Data handling and model providers

Understand where your data goes.

Separate what is stored by Zograph, what is processed during an agent run, and what is sent to model providers or connected services.

Storage and protection

Review the data categories held by the service and the scope of storage and transport protections.

Provider data use

Distinguish Zograph’s policy from the terms and settings of the selected model connection.

Retention and deletion

Understand the treatment of content, records, operational logs and backups.

Bring-your-own credentials are not a data-use policy.

Retention, training use and processing location depend on the selected connection and applicable arrangements.

04Credentials and connected systems

Connections with explicit authority.

Understand whose credentials a connection uses, which tools it exposes and how its permissions are managed. Access in a source system and permission to invoke a tool are separate controls.

Organization-level connection

A connection acts with the authority granted to its configured service credentials.

Review

  • Source-system permissions
  • Connection administrators
  • Available tools and actions

User-delegated connection

Where available and configured, the connection uses access delegated by an individual user.

Review

  • Delegated scope
  • Identity and session lifecycle
  • Revocation behavior

Credential handling

How secrets are stored, accessed and excluded from inappropriate outputs.

Rotation and revocation

Which changes can be made and when they take effect.

Connection trust

How tool metadata and connected services enter the trust model.

Tool annotations are not independent verification.

A server’s description of an action and the policy that authorizes its use are different things. Review what the configuration chooses to trust.

05Agent actions and records

Define authority beyond the conversation.

A proposed action, its permission decision, the required approval and its execution result should be understood separately.

An action through its control points

Illustrative sequence

  1. Request

    The agent proposes a tool action.

  2. Policy

    The applicable permission is evaluated.

  3. Authority

    A required person or system decides.

  4. Execution record

    The tool outcome is recorded separately.

  • Allowed
  • Requires approval
  • Denied

Different outcomes, not different labels for the same action.

What authorized the action?

Identify the relevant permission source and any recorded approval authority.

What actually happened?

Distinguish approval from an attempted action, a completed execution or an error.

Controls have a defined scope.

A tool restriction does not establish database row-level security or prove that every disclosure path has been prevented.

06Deployment, residency and responsibilities

Know the boundaries of your deployment.

Review the operating arrangement, processing locations and responsibilities for the configuration you intend to use.

  • Service operation

    Which application and operational controls are managed by Zograph.

  • Customer configuration

    Which identities, tools, source-system permissions and destinations you control.

  • Customer-managed components

    Which responsibilities change where a customer-operated arrangement is available.

  • External providers

    Which processing behaviors depend on the chosen service and configuration.

A hosting region is not the entire residency story.

Model inference, external tools, operational records and backups need their own documented scope.

07Secure development and service operations

Security in how the service is developed and operated.

Product controls are one part of the assessment. Review the established practices for changes, operational access, vulnerability handling and recovery.

Development and change

Review how changes are assessed, security-sensitive behavior is tested and dependencies are maintained.

  • Changes
  • Testing
  • Dependencies

Vulnerability handling

Understand how reported or discovered vulnerabilities are assessed, prioritized and addressed.

  • Reporting
  • Triage
  • Remediation

Operational access

Review elevated access, security-relevant monitoring and the handling of privileged activity.

  • Access
  • Monitoring
  • Review

Recovery and incidents

Discuss documented backup, restoration and incident-handling arrangements for the service.

  • Backups
  • Restoration
  • Communication

Evidence and commitments should be specific.

Assessment dates, testing scope, recovery objectives and response commitments belong to verified procedures and applicable agreements.

08Assurance and security inquiries

Review the details that matter to your deployment.

Start with the public overview, then discuss the supporting information and deployment-specific requirements relevant to your security review.

Supporting information to review

  • Privacy and processing

    The relevant notices and data-processing arrangements.

  • Providers and data paths

    Applicable third parties and configuration-specific processing.

  • Technical and operational scope

    Further detail supporting the controls described here.

  • Assessments, where available

    The exact scope and date of any verified assurance material.

Discuss security requirements

Share the intended deployment and the questions your team needs to assess.

Report a security issue

A dedicated reporting route should remain separate from product and sales inquiries.

Reporting channel and response commitments to be confirmed before publication.

Only verified, scoped assurance material should be listed. A provider’s certification is not Zograph’s certification.