Safe, isolated, and provable.

Xybern decides whether every agent action runs, so we secure the layer itself, at every hop, with encryption, isolation, and a signed record you can verify. Your operations are nobody else’s business.

SOC 2Type II certified
AES-256Encryption at rest
TLS 1.3In transit
100%Tenant isolation
Inline by design

We sit in the execution path. Here is what that means.

Because Xybern is inline, not alongside, we answer the question every architect asks first: what if Xybern itself fails? Explicitly, by design.

Fail-closed by default

If Xybern is unreachable, actions queue at the boundary. Nothing slips through, and there is no fail-open mode by default.

Cryptographic tenant isolation

Workspace keys are scoped at the HSM level. Cross-workspace access returns a hard 403, an architectural impossibility, not a policy call.

Metadata, not content

The evaluation engine sees the action type, the agent identity, the trust context, and the policy. It never receives the content of the action.

No enforcement gaps

Isolation is the default state at storage, compute, network, and queue, from the moment a workspace is provisioned.

Compliance

Third-party validated. Continuously monitored.

We share our controls, reports, and test results with your security and procurement teams directly. No NDA for the initial architecture review.

SOC 2 Type II

Annual third-party audit of security, availability, and confidentiality controls.

Request report

GDPR ready

Data processing agreements available. EU residency ensures no transatlantic transfer, with right to erasure for non-vault data.

Request DPA

Penetration tested

Regular third-party penetration testing with full remediation tracking.

Request summary

Cryptographic audit trail

Every verification is SHA-256 hashed, HMAC-signed, and chain-linked. Tamper-evident by construction, not by policy.

Encryption

Every hop. Every layer. Encrypted.

A single agent action is encrypted at every stage, from the call into Xybern, through the evaluation engine, to the vault entry. No plaintext at rest.

TLS 1.3 everywhere

Every ingress and egress path uses TLS 1.3 with modern cipher suites. Certificate pinning is available for private deployments.

AES-256 envelope encryption

Data at rest uses envelope encryption with scheduled key rotation. Keys rotate without disrupting existing vault entries.

Field-level protection

Selective encryption for sensitive fields within enforcement records, zeroized when the evaluation pipeline completes.

Customer-managed keys

Bring your own keys via your KMS or HSM. Provision, rotate, revoke, and attest, with every key event recorded in the vault.

Isolation & deployment

Choose the boundary that matches your risk.

Tenant isolation is the default, not an add-on. Escalate to dedicated pools, HSM-backed keys, or run the whole layer inside your own infrastructure.

Isolation tiers

Standard, Enhanced, Dedicated, and Dedicated plus HSM, isolating storage, compute, networking, and queues.

Self-hosted relay

Evaluate policies locally and forward only what you must, keeping enforcement close to your systems.

On-premise & air-gapped

Full on-premise or air-gapped deployment with no external dependency.

Data residency

Pin data to the US, EU, or UK, with workspace isolation at every layer.

Identity & access

Only the right people, only the right access.

Authenticate through your identity provider, provision automatically, and restrict how and where people and agents sign in.

Single sign-on

Authenticate through Google or your OIDC provider, or email codes.

SAML

SAML via most identity providers, including Okta, Entra, OneLogin, and more.

SCIM provisioning

Provision and deprovision users automatically from your directory.

Roles and scoped access

Role-based access with scoped, time-bound permissions for both people and agents.

IP restrictions

Restrict workspace access to your private network.

Breakglass with justification

Emergency access requires a named human and a recorded justification, sealed to the vault.

Provenance & audit

Every decision, sealed and verifiable.

Each authorisation is written once to a hash-chained vault and can be verified on your own, without trusting us.

Signed authorisation receipts

Every decision produces a signed, offline-verifiable receipt of what was allowed, escalated, or blocked.

Hash-chained vault

Records are chain-linked and append-only. Any later change breaks the chain, which is how tampering is detected.

Offline verification

Verify any record with the public key. No call back to Xybern is required.

Exportable proof packs

Export a scoped, signed pack for any period, agent, or single decision.

Sample audit log

Ready when your security team is.

We share architecture documentation, penetration test reports, and SOC 2 Type II directly with security and procurement. No NDA for the initial architecture review.