[01]TENANT_ISOLATIONLogical (and optional physical) isolation per customer · No cross-tenant model memory · Per-tenant encryption keysOK
[02]DATA_PROTECTIONTLS 1.2+ in transit · AES-256 at rest · Configurable retention · Customer-managed deletionOK
[03]ACCESS_CONTROLSSO via SAML 2.0 and OIDC · RBAC per resource · Service accounts with scoped, rotatable keysOK
[04]AUDIT_TRAILEvery agent decision logged: input, tool calls, model output, downstream effects · Exportable, immutableOK
[05]DEPLOYMENTManaged cloud or customer VPC · In VPC mode no execution data leaves the customer perimeterOK