Autonomous agents touching your systems is a security question first and a product question second. Here is exactly how LeafMesh protects your data, where it runs, and what we hold today versus what's in flight — stated plainly, with no certification we don't have.
TLS 1.2+ in transit; AES-256 at rest where the operator brings encryption. No plaintext data crosses a trust boundary.
Sensitive fields are redacted before they reach a model or leave your collector. Telemetry payload bodies stay in your environment unless you opt in.
Every agent action, routing decision, and human approval is written to an immutable, timestamped log — reconstructable end to end for a review.
Role-based access on the hosted Studio, per-key API scoping, and tier separation as a hard security boundary between build and runtime surfaces.
Inbound webhooks are signed with HMAC-SHA256 and protected against replay — no unauthenticated command reaches the mesh.
Data retention is configurable per environment, and deletion is customer-initiated. Your data is never used to train our models.
The strongest control is where the work runs. LeafMesh deploys from fully hosted to fully air-gapped — so sensitive data never has to leave your boundary.
Fully managed, monitored, and updated by us. The fastest path to production.
Runs inside your own cloud account — your network, your keys, your logs.
Self-hosted in your data center for the strictest data-control regimes.
No outbound calls leave your environment — for classified and isolated networks.
Your data never trains our models.
Data residency is enforced by region and tier separation. Your prompts, documents, and agent outputs are never used to train, retrain, or fine-tune any model — ours or a provider's.
We publish exactly where we are. A supported posture is not a certification, and we mark the difference so your security team never has to guess.
GDPR / CCPA
Data residency via tier separation, customer-controlled deletion, default-on PII redaction. A posture the platform supports — your DPO still owns the regime.
HIPAA primitives
TLS, audit logging, access control and PII handling are in place. A production deployment still requires a BAA with your Redis and LLM providers.
Bring your own model & keys
Run on your own LLM provider and credentials. Your prompts, data, and outputs stay on your provider bills — not ours.
SOC 2 Type II
Audit plannedControls are designed against CC6.1, CC7.2 and CC7.5. An independent audit is planned; no Type II report is available yet.
ISO 27001 / 27018
Aligned, not certifiedControls align with A.9, A.12.4, A.13.2, A.17 and the 27018 PII annex. Certification is not yet pursued.
PCI DSS
Not pursuedCard data should not transit LeafMesh; tokenize at the channel edge before the agent layer ever sees it.
The fastest deals run security and legal in parallel with the pilot — not after it. Tell us what your review needs and we'll share what's available today and what's in flight.
Enterprise engagements include a Master Services Agreement scoped to your workflow, a dedicated ops engineer, and a custom SLA.
Available on request
We use cookies to enhance your browsing experience, analyze site traffic, and provide personalized content. "Accept All" consents to our use of cookies.