The lane IT can trust.
Salus exists so security can say "yes" to AI without losing control. Here's how the lane stays governed — and where our compliance program stands.
Where our program stands today.
We're straight about status: our audits are in their final stages, not yet complete. Here's exactly where things are.
SOC 2 Type II
In progressAudit completing — report expected August 2026
ISO 27001
In progressAudit completing — certification expected August 2026
Penetration testing
In progressIndependent third-party tests via our compliance program · reports under NDA
SOC 2 Type II and ISO 27001 audits are both in their final stages, with reports expected in August 2026. Compliance is monitored continuously in Vanta, and penetration testing is performed by independent third parties. We'll publish reports and certificates here as they're issued — and share current documentation under NDA in the meantime.
Governed by default. For humans and agents.
The controls that let you hand a lane to every team and every agent without losing the plot — set once, inherited by every app.
Your rules, enforced
RBAC · humans & agents
Policy gates
Release window
humans + agents · weekdays 06–20 UTC
Vulnerability scan
0 critical allowed
Egress to unlisted API
external network · not allow-listed
Blast radius
This deploy touches
3 / 12 services
within limit · cap 12 services
Last resort
Kill switch
any app · any agent · instant
Audit trail
Role-based access control
Scope what every person can deploy, reach and change, at organisation, space and project level. An agent acts with its builder’s access, so it inherits those bounds and can never exceed them.
Encrypted secrets
Secrets encrypted at rest and in transit, injected at runtime — never stored in code or logs.
Isolation & controls
Each workload runs isolated, with its own credentials and network boundary, so what one app can reach is bounded before it runs.
Audit & observability
Audit events are written append-only — never edited or deleted — isolated per tenant, each recording the actor and the time. Any deployment can be pulled offline instantly.
Who owns what — in plain terms.
The question every security questionnaire asks first, answered before you ask it.
You own
- Your cloud account and IAM (Enterprise/BYOC)
- Your data and your databases
- Your policies — who may build, deploy, and promote
Salus operates
- The platform: builds, pipelines, runtime, upgrades
- The governance controls: roles, isolation, audit storage, an off switch
- Monitoring, patching, and vulnerability management
You both see
- The full audit trail — every human and agent action
- Observability: logs, metrics, costs per workload
- Compliance documentation, shared under NDA today
Your data never leaves your cloud.
Salus Enterprise runs single-tenant inside your own AWS, GCP, Azure, or Huawei account (BYOC). Apps, data, and secrets stay within your perimeter and your compliance boundary — in whatever region your obligations require, from the US to the EU to Africa. Residency isn't a feature tier; it's a consequence of the architecture.
The governed lane sits alongside production — never inside it.
Need our security documentation?
We'll walk your security team through the architecture, share our controls and current audit status, and provide documentation under NDA. No pitch deck.