Security

Inside your permissions, your cloud, and your audit trail.

Built by people who have run enterprise systems for thirty years. Everything an agent does happens inside the permissions of the person who started it, inside your cloud, and on record.

A platform built for security.

Sandboxed.

By default.

An agent gets the permissions of the person who started it, and nothing more. Credentials are scoped. Calls are rate limited.

Versioned,

promoted, audited.

A change is a diff a reviewer can read. Nothing reaches production without passing a check at each gate.

Every dollar

attributed.

Spend by agent, by run, and by team, next to the work it paid for.

Runs where

your data lives.

AWS, Azure, GCP, Kubernetes, or your own servers. Traces go to the observability stack you already run, over OpenTelemetry.

Switch models

when the evidence says so.

Each task runs on the model our benchmarks rank best for it. When a cheaper one catches up, you move over without rebuilding the agent.

Sandboxed. By default.

An agent gets the permissions of the person who started it, and nothing more. Credentials are scoped. Calls are rate limited.

Credential scopingRate limitingPermission inheritance

Versioned, promoted, audited.

A change is a diff a reviewer can read. Nothing reaches production without passing a check at each gate.

Change reviewStaged promotionAudit trail

Every dollar attributed.

Spend by agent, by run, and by team, next to the work it paid for.

Cost by agentCost by teamBudget alerts

Runs where your data lives.

AWS, Azure, GCP, Kubernetes, or your own servers. Traces go to the observability stack you already run, over OpenTelemetry.

Cloud or on-premKubernetes nativeOpenTelemetry traces

Switch models when the evidence says so.

Each task runs on the model our benchmarks rank best for it. When a cheaper one catches up, you move over without rebuilding the agent.

Continuous benchmarkingAutomatic routingSwap without rework

The controls, in detail

Permissions

An agent gets the permissions of the person who started it, and nothing more. Credentials are scoped per connection. Calls are rate limited.

Approvals

Anything with money or a customer on the line waits for a named approver. Approval points are part of the agent's definition, not a setting someone can forget.

Change control

A change is a diff a reviewer can read. Nothing reaches production without passing a check at each gate: dev, staging, production.

Audit trail

Each run records what the agent read, what it did, and what it cost. Traces go to the observability stack you already run, over OpenTelemetry.

Where it runs

AWS, Azure, GCP, Kubernetes, or your own servers. Your data stays where it lives. Model calls go only to the providers you allow.

Cost controls

Spend by agent, by run, and by team, with budget alerts, so a runaway agent is a notification and not a surprise on the invoice.

Certifications

SOC 2 certification is in progress. We'll publish the report here when it's issued. Until then, our security team will walk yours through the controls above and answer a questionnaire directly.

Report a vulnerability

If you've found something, write to contact@agentdynamo.com with the details. We read every report and reply.

Bring us your security questionnaire.

We’ll give you automated workflow agents.