The agent never holds write credentials, tenant isolation is enforced in the database, outbound calls are allow-listed, secrets are encrypted and evidence is append-only. These are properties of the system, not settings.
Only COLVO’s executor holds provider write access. The agent proposes against a mandate registered by your trusted backend — a chat-supplied id is never enough.
Org identity comes from the authenticated session and is enforced with Postgres row-level security on every tenant table. The application database role cannot bypass it. Cross-account access is denied in UI, API, export and worker alike.
Only approved hosts. Localhost, private and cloud-metadata ranges are blocked, DNS answers are pinned and redirects re-checked — SSRF-hardened by default, including the call to your own agent.
Provider and AI keys are encrypted at rest, scoped to one organisation and never written to logs, prompts or exports. Every decision and action is logged append-only; the compliance report is SHA-256 chained and recomputable.
Found something? Write to [email protected]. We acknowledge within two business days and keep you informed until it is fixed. Please do not test against other customers’ organisations.
COLVO is in pilot. There is no SOC 2 report yet, no penetration test report to share, and the first provider integration is Stripe. The compliance export is designed to make an audit easier; it is not itself a certification. We would rather tell you this on the security page than in a sales call.
Architecture review, data-flow diagram, threat model — we walk your security team through all of it.