Content-minimizing audit
Full prompts and responses are excluded from audit storage by default. Content retention must be explicitly enabled and requires a dedicated view-content permission.
Default: content offTrust center
Entrovik is built for a privileged position in enterprise infrastructure. This page states what the product enforces today, what the operator controls, and what must be validated for each deployment.
Current control posture
These are product capabilities, not claims of customer certification or a substitute for your control environment.
Full prompts and responses are excluded from audit storage by default. Content retention must be explicitly enabled and requires a dedicated view-content permission.
Default: content offAPI keys are stored as hashes. OIDC validates issuer, audience, token signature, and expiry before mapping claims into a tenant-scoped identity and roles.
Enforced server-sidePolicies, pipelines, providers, identities, audit records, and usage queries carry tenant scope. Cross-tenant negative tests cover administrative boundaries.
Not a UI filterExternal policies receive a versioned JSON ABI and no filesystem, network, environment, process, or arbitrary host capability by default.
wazero; no CGO requiredPackages validate manifests and ABI, verify SHA-256 integrity, enforce publisher trust, and support Ed25519 signatures and trusted public keys.
Unsigned denial configurableTenant audit chains include previous and current record hashes. PostgreSQL writers serialize each tenant chain across replicas; integrity is independently verifiable.
Content-free evidenceProvider credentials are resolved from environment, Kubernetes, Vault, AWS, Azure, or Google secret references and are not returned by administrative APIs.
No secret response fieldsBody, time, memory, output, initialization, execution, and concurrency limits contain malformed traffic and defective policies. Failure policy is explicit.
Fail closed availableShared responsibility
Security depends on both product behavior and the environment where the gateway runs.
Secure headers and configurable TLS boundaries
Certificates, private networking, ingress, and provider/database TLS
API-key and OIDC verification with RBAC checks
Identity-provider configuration, group claims, lifecycle, and access review
SQLite and PostgreSQL abstractions, migrations, tenant scope, retention controls
Managed database hardening, backup, restore, PITR, and geographic policy
Sandboxing, package validation, signatures, publisher trust, and failure policy
Policy selection, configuration review, false-positive testing, and approvals
Health, readiness, Prometheus metrics, and structured logs
Collection, alert routing, SLOs, incident response, and retention
Review package
We will not imply a certification that has not been earned. We will provide precise technical evidence and identify any procurement requirement that still needs work.
Honest answers
This page does not claim SOC 2 certification. Ask us for the current assurance roadmap and available technical evidence for the release you are evaluating.
No product makes an organization compliant by itself. Entrovik can enforce and evidence relevant technical controls, but legal basis, process, contracts, configuration, and organizational controls remain customer responsibilities.
The public playground is for synthetic data. It evaluates submitted content in memory, does not call an AI provider, and does not store that content in Entrovik audit records.
Yes. Enterprise reviews should cover the exact image, Helm values, network boundaries, identity configuration, persistence topology, policy packages, trust roots, secret references, and retention settings.

Security review
Map the platform to your architecture, procurement controls, and unresolved requirements.