Security & Trust

Security you can verify.

Autonomous agents touching your systems is a security question first and a product question second. Here is exactly how LeafMesh protects your data, where it runs, and what we hold today versus what's in flight — stated plainly, with no certification we don't have.

Controls in place today

The controls that ship in every deployment

Encryption everywhere

TLS 1.2+ in transit; AES-256 at rest where the operator brings encryption. No plaintext data crosses a trust boundary.

PII redaction, default-on

Sensitive fields are redacted before they reach a model or leave your collector. Telemetry payload bodies stay in your environment unless you opt in.

Append-only audit trail

Every agent action, routing decision, and human approval is written to an immutable, timestamped log — reconstructable end to end for a review.

Access control

Role-based access on the hosted Studio, per-key API scoping, and tier separation as a hard security boundary between build and runtime surfaces.

Webhook security

Inbound webhooks are signed with HMAC-SHA256 and protected against replay — no unauthenticated command reaches the mesh.

Customer-controlled retention

Data retention is configurable per environment, and deletion is customer-initiated. Your data is never used to train our models.

Runs in your environment

Your agents. Your infrastructure. Your data.

The strongest control is where the work runs. LeafMesh deploys from fully hosted to fully air-gapped — so sensitive data never has to leave your boundary.

LeafCraft-hosted

Fully managed, monitored, and updated by us. The fastest path to production.

Your VPC

Runs inside your own cloud account — your network, your keys, your logs.

On-premises

Self-hosted in your data center for the strictest data-control regimes.

Air-gapped

No outbound calls leave your environment — for classified and isolated networks.

Your data never trains our models.

Data residency is enforced by region and tier separation. Your prompts, documents, and agent outputs are never used to train, retrain, or fine-tune any model — ours or a provider's.

Compliance posture

What we support — and what's on the roadmap

We publish exactly where we are. A supported posture is not a certification, and we mark the difference so your security team never has to guess.

Supported today
  • GDPR / CCPA

    Data residency via tier separation, customer-controlled deletion, default-on PII redaction. A posture the platform supports — your DPO still owns the regime.

  • HIPAA primitives

    TLS, audit logging, access control and PII handling are in place. A production deployment still requires a BAA with your Redis and LLM providers.

  • Bring your own model & keys

    Run on your own LLM provider and credentials. Your prompts, data, and outputs stay on your provider bills — not ours.

On the roadmap — not delivered
  • SOC 2 Type II

    Audit planned

    Controls are designed against CC6.1, CC7.2 and CC7.5. An independent audit is planned; no Type II report is available yet.

  • ISO 27001 / 27018

    Aligned, not certified

    Controls align with A.9, A.12.4, A.13.2, A.17 and the 27018 PII annex. Certification is not yet pursued.

  • PCI DSS

    Not pursued

    Card data should not transit LeafMesh; tokenize at the channel edge before the agent layer ever sees it.

For your review

Bring your security & procurement team early

The fastest deals run security and legal in parallel with the pilot — not after it. Tell us what your review needs and we'll share what's available today and what's in flight.

Enterprise engagements include a Master Services Agreement scoped to your workflow, a dedicated ops engineer, and a custom SLA.

Available on request

  • SIG-Lite questionnaire
  • CAIQ (Cloud Controls Matrix)
  • Penetration-test summary letter
  • Master Services Agreement (enterprise)
  • Architecture & data-flow walkthrough
Talk to our team