Isolation & trust

A control that can be bypassed protects nothing.

The agent never holds write credentials, tenant isolation is enforced in the database, outbound calls are allow-listed, secrets are encrypted and evidence is append-only. These are properties of the system, not settings.

01 — PRINCIPLES
Non-negotiables

Built into the product, not bolted on.

MANDATED WRITES

The agent can’t write directly

Only COLVO’s executor holds provider write access. The agent proposes against a mandate registered by your trusted backend — a chat-supplied id is never enough.

TENANT ISOLATION

Nothing leaks across organisations

Org identity comes from the authenticated session and is enforced with Postgres row-level security on every tenant table. The application database role cannot bypass it. Cross-account access is denied in UI, API, export and worker alike.

EGRESS CONTROL

Locked-down outbound calls

Only approved hosts. Localhost, private and cloud-metadata ranges are blocked, DNS answers are pinned and redirects re-checked — SSRF-hardened by default, including the call to your own agent.

SECRETS & EVIDENCE

Encrypted, scoped, append-only

Provider and AI keys are encrypted at rest, scoped to one organisation and never written to logs, prompts or exports. Every decision and action is logged append-only; the compliance report is SHA-256 chained and recomputable.

02 — CONTROLS
Controls

What is in place today

Access

  • Invite-only accounts; password with policy checks or magic link; no account enumeration on any auth email
  • Org roles owner / editor / viewer enforced on every write
  • Superadmin (COLVO staff) is an exclusive role: never a member of a client organisation, works in a separate console
  • API keys are hashed at rest, scoped (backend / agent), shown once, revocable and rotatable
  • Activity log of sign-ins, key and role changes, plan changes and decisions

Data

  • Pilots run on simulated Stripe data; production Guard reads real state read-only for verification
  • Per-organisation export and deletion on request; 30-day retention job for test artefacts
  • PII redaction available as an input and output guardrail

Reliability

  • Idempotency: business key + budget reservation + transactional outbox; a retry never doubles an effect
  • No open database transaction across a network call
  • Reconciliation from provider state after crashes, timeouts and provider review
  • Deterministic verdicts need no AI; AI judges are metered, capped and advisory
  • Production refuses to boot on a missing or development session secret

Disclosure

Found something? Write to [email protected]. We acknowledge within two business days and keep you informed until it is fixed. Please do not test against other customers’ organisations.

03 — HONEST LIMITS
What we do not claim

Where we are

COLVO is in pilot. There is no SOC 2 report yet, no penetration test report to share, and the first provider integration is Stripe. The compliance export is designed to make an audit easier; it is not itself a certification. We would rather tell you this on the security page than in a sales call.

Terms   Privacy

≠

Ask us the hard questions.

Architecture review, data-flow diagram, threat model — we walk your security team through all of it.

Security — a control that can be bypassed protects nothing · COLVO