Salus
Security & Trust

The lane IT can trust.

Salus exists so security can say "yes" to AI without losing control. Here's how the lane stays governed — and where our compliance program stands.

Compliance

Where our program stands today.

We're straight about status: our audits are in their final stages, not yet complete. Here's exactly where things are.

SOC 2 Type II

In progress

Audit completing — report expected August 2026

ISO 27001

In progress

Audit completing — certification expected August 2026

Penetration testing

In progress

Independent third-party tests via our compliance program · reports under NDA

SOC 2 Type II and ISO 27001 audits are both in their final stages, with reports expected in August 2026. Compliance is monitored continuously in Vanta, and penetration testing is performed by independent third parties. We'll publish reports and certificates here as they're issued — and share current documentation under NDA in the meantime.

Platform security

Governed by default. For humans and agents.

The controls that let you hand a lane to every team and every agent without losing the plot — set once, inherited by every app.

Your rules, enforced

org-policy · production lane

RBAC · humans & agents

[email protected]builder
deploylogsenv vars
claude-codeagent-builder
deployrollbacklogs

Policy gates

Release window

humans + agents · weekdays 06–20 UTC

passedblockedpendingwaiting

Vulnerability scan

0 critical allowed

passedblockedpendingwaiting

Egress to unlisted API

external network · not allow-listed

passedblockedpendingwaiting

Blast radius

This deploy touches

3 / 12 services

within limit · cap 12 services

Last resort

Kill switch

any app · any agent · instant

armed

Audit trail

agent · mcpclaude-codedeploy14:02 UTC
human[email protected]env var set13:47 UTC
agent · mcpops-copilotrollback11:20 UTC

Role-based access control

Scope what every person can deploy, reach and change, at organisation, space and project level. An agent acts with its builder’s access, so it inherits those bounds and can never exceed them.

Encrypted secrets

Secrets encrypted at rest and in transit, injected at runtime — never stored in code or logs.

Isolation & controls

Each workload runs isolated, with its own credentials and network boundary, so what one app can reach is bounded before it runs.

Audit & observability

Audit events are written append-only — never edited or deleted — isolated per tenant, each recording the actor and the time. Any deployment can be pulled offline instantly.

Shared responsibility

Who owns what — in plain terms.

The question every security questionnaire asks first, answered before you ask it.

You own

  • Your cloud account and IAM (Enterprise/BYOC)
  • Your data and your databases
  • Your policies — who may build, deploy, and promote

Salus operates

  • The platform: builds, pipelines, runtime, upgrades
  • The governance controls: roles, isolation, audit storage, an off switch
  • Monitoring, patching, and vulnerability management

You both see

  • The full audit trail — every human and agent action
  • Observability: logs, metrics, costs per workload
  • Compliance documentation, shared under NDA today

Your data never leaves your cloud.

Salus Enterprise runs single-tenant inside your own AWS, GCP, Azure, or Huawei account (BYOC). Apps, data, and secrets stay within your perimeter and your compliance boundary — in whatever region your obligations require, from the US to the EU to Africa. Residency isn't a feature tier; it's a consequence of the architecture.

The governed lane sits alongside production — never inside it.

Need our security documentation?

We'll walk your security team through the architecture, share our controls and current audit status, and provide documentation under NDA. No pitch deck.