Security & Compliance

How Altheris is designed to keep your agents — and your data — provably secure.

Infrastructure

Built to be EU-hosted on Supabase (eu-west-2, London), with all data encrypted at rest and in transit over TLS.

Cryptographic Security

Every agent is designed to be issued a signed Ed25519 identity passport, with all actions recorded in a tamper-evident hash chain.

On-Chain Anchoring

Receipt hashes are designed to be periodically anchored to the Polygon blockchain, giving you independent, verifiable proof of integrity.

Access Control

Row Level Security is built to isolate every account's data, with strict service-role separation and role-based access control (RBAC) for teams.

Compliance

GDPR data residency in the EU, with a complete audit log of account events and one-click compliance reports designed for your records.

SDK Security

Built so you can wrap any agent in two lines of code to activate all 13 runtime security features — listed below.

Responsible Disclosure

We welcome reports from security researchers. If you believe you've found a vulnerability, please email team@altheris.io with details and steps to reproduce. We will acknowledge your report and keep you updated through resolution. Please give us reasonable time to remediate before any public disclosure.