Security-first, and honest about it
Sageros sits between your agents and model providers, so security matters at every hop. We are early, so this page does something most vendors avoid: it states plainly what runs today and what is still on the roadmap - no compliance badges we have not earned.
Inline PII redaction
Our first shipping capability. Structured PII - emails, phone numbers, and card data - is detected and masked before a prompt leaves for the model. Detection is deterministic for these structured types; free-text names and addresses are best-effort, not a guarantee. We would rather tell you that than pretend otherwise.
Cloud gateway (URL + key)
Point your agent's base URL at Sageros and use a key we issue. In this model your requests and provider keys pass through our cloud - so we are the custodian, and we say so directly. Encryption in transit (TLS) and at rest applies. Self-hosting, where nothing leaves your network, is on the roadmap below.
Self-hosted deployment
Run Sageros as a node inside your own network so raw prompts and provider keys never cross your security boundary. Planned, so that regulated teams can adopt it without sending data to us.
Envelope encryption (KMS)
Wrapping each stored provider key with a customer-controlled master key, so a database leak alone reveals nothing usable. Planned as we harden key custody in the cloud model.
Session governance
Grouping every model and tool call under one session, breaking runaway loops, and holding destructive tool calls for human approval. In active design - see the platform page for the full vision.
Data handling today
Our design goal is that the least amount of sensitive data travels the shortest distance: prompts are inspected in memory, redaction is applied at the gateway, and only the required payload is forwarded to your chosen model provider. In the current cloud model, that traffic passes through Sageros infrastructure.
- In transit: traffic is encrypted with TLS.
- At rest: stored records are encrypted.
- Provider keys: held to make calls on your behalf in the cloud model. Envelope encryption with a customer-controlled master key is on the roadmap, not in place yet.
- Retention: we are keeping stored data minimal by default while the product is early.
Compliance - where we honestly stand
We do not hold any compliance certification today, and we will not display a badge we have not earned. Here is the real status:
- SOC 2: on our roadmap. We are building toward it, but we are not SOC 2 audited yet.
- GDPR: we are designing for data-residency controls and EU-data egress handling. We are not making a compliance claim at this stage.
If a formal certification is a hard requirement for you right now, we are not the right fit yet - and we would rather say that than lose your trust later.
Responsible disclosure
Found a vulnerability? We want to hear from you. Email office@sageros.com and our team will respond within one business day. We do not pursue legal action against good-faith researchers who follow coordinated disclosure.