Infrastructure
Built to be EU-hosted on Supabase (eu-west-2, London), with all data encrypted at rest and in transit over TLS.
Cryptographic Security
Every agent is designed to be issued a signed Ed25519 identity passport, with all actions recorded in a tamper-evident hash chain.
On-Chain Anchoring
Receipt hashes are designed to be periodically anchored to the Polygon blockchain, giving you independent, verifiable proof of integrity.
Access Control
Row Level Security is built to isolate every account's data, with strict service-role separation and role-based access control (RBAC) for teams.
Compliance
GDPR data residency in the EU, with a complete audit log of account events and one-click compliance reports designed for your records.
SDK Security
Built so you can wrap any agent in two lines of code to activate all 13 runtime security features — listed below.
13 SDK Security Features
Designed to activate instantly when you wrap an agent with the Altheris SDK.
Responsible Disclosure
We welcome reports from security researchers. If you believe you've found a vulnerability, please email team@altheris.io with details and steps to reproduce. We will acknowledge your report and keep you updated through resolution. Please give us reasonable time to remediate before any public disclosure.
Need a security review?
Enterprise teams can request architecture documentation and a dedicated security review.