Trust center

Concrete controls. No borrowed compliance badges.

Entrovik is built for a privileged position in enterprise infrastructure. This page states what the product enforces today, what the operator controls, and what must be validated for each deployment.

Product security statusNo known unresolved critical product vulnerabilityStatement generated for the current published product posture; customers should validate the exact release they deploy.

Current control posture

Security that exists in code and deployment boundaries.

These are product capabilities, not claims of customer certification or a substitute for your control environment.

DATA

Content-minimizing audit

Full prompts and responses are excluded from audit storage by default. Content retention must be explicitly enabled and requires a dedicated view-content permission.

Default: content off
IDENTITY

API keys and OIDC

API keys are stored as hashes. OIDC validates issuer, audience, token signature, and expiry before mapping claims into a tenant-scoped identity and roles.

Enforced server-side
ISOLATION

Tenant-scoped persistence

Policies, pipelines, providers, identities, audit records, and usage queries carry tenant scope. Cross-tenant negative tests cover administrative boundaries.

Not a UI filter
POLICIES

Capability-denied WASM

External policies receive a versioned JSON ABI and no filesystem, network, environment, process, or arbitrary host capability by default.

wazero; no CGO required
SUPPLY CHAIN

Integrity and trust admission

Packages validate manifests and ABI, verify SHA-256 integrity, enforce publisher trust, and support Ed25519 signatures and trusted public keys.

Unsigned denial configurable
AUDIT

Tamper-evident records

Tenant audit chains include previous and current record hashes. PostgreSQL writers serialize each tenant chain across replicas; integrity is independently verifiable.

Content-free evidence
SECRETS

Reference-based credentials

Provider credentials are resolved from environment, Kubernetes, Vault, AWS, Azure, or Google secret references and are not returned by administrative APIs.

No secret response fields
OPERATIONS

Safe failure boundaries

Body, time, memory, output, initialization, execution, and concurrency limits contain malformed traffic and defective policies. Failure policy is explicit.

Fail closed available

Shared responsibility

Entrovik enforces policy. Your deployment completes the control.

Security depends on both product behavior and the environment where the gateway runs.

ControlEntrovik providesOperator owns
Transport

Secure headers and configurable TLS boundaries

Certificates, private networking, ingress, and provider/database TLS

Identity

API-key and OIDC verification with RBAC checks

Identity-provider configuration, group claims, lifecycle, and access review

Persistence

SQLite and PostgreSQL abstractions, migrations, tenant scope, retention controls

Managed database hardening, backup, restore, PITR, and geographic policy

Policies

Sandboxing, package validation, signatures, publisher trust, and failure policy

Policy selection, configuration review, false-positive testing, and approvals

Monitoring

Health, readiness, Prometheus metrics, and structured logs

Collection, alert routing, SLOs, incident response, and retention

Review package

Evidence we can walk through with your reviewers.

We will not imply a certification that has not been earned. We will provide precise technical evidence and identify any procurement requirement that still needs work.

01Architecture and data-flow review02Threat boundaries and WASM runtime controls03RBAC permission matrix and tenant-isolation tests04Audit schema, retention, and integrity verification05Container, Kubernetes, and Helm security posture06Dependency vulnerability scan and SBOM workflow07Backup, restore, migration, and HA qualification evidence

Honest answers

Trust questions deserve precise language.

Is Entrovik SOC 2 certified?

This page does not claim SOC 2 certification. Ask us for the current assurance roadmap and available technical evidence for the release you are evaluating.

Is using Entrovik enough to make us HIPAA, PCI DSS, or GDPR compliant?

No product makes an organization compliant by itself. Entrovik can enforce and evidence relevant technical controls, but legal basis, process, contracts, configuration, and organizational controls remain customer responsibilities.

Does the website collect prompt data?

The public playground is for synthetic data. It evaluates submitted content in memory, does not call an AI provider, and does not store that content in Entrovik audit records.

Can we review the exact deployment configuration?

Yes. Enterprise reviews should cover the exact image, Helm values, network boundaries, identity configuration, persistence topology, policy packages, trust roots, secret references, and retention settings.

Security review

Bring the questionnaire. We’ll bring evidence.

Map the platform to your architecture, procurement controls, and unresolved requirements.