Trust

Controls you can ask to see.

Start with the trust boundary.We review who will share the deployment and what must be separated. Different agent names are not a substitute for tenant isolation.
Define authority before access.Agree credential scopes, permitted tools, and human approvals for consequential actions. Verify the controls against the actual workflow.
Trace where the data goes.Review workspace storage, external providers, logs, retention, and deletion requirements. Self-hosting alone does not guarantee that data never leaves the host.
Make operations accountable.Specify maintenance, incident handling, backup and recovery, and exit responsibilities in the engagement. Support commitments are agreed in writing.
Say what is verified.We do not claim SOC 2, ISO 27001, regulatory compliance, or universal SSO coverage. Any certification, custom identity integration, or audit requirement must be assessed explicitly.
Discuss your deployment requirements

Independent implementation. Documented scope. No implied certification.