Security at Actori
Actori is the control plane that governs what AI agents can do — we hold it to the standard we sell.
Data protection
In transit
At rest
Your agents don’t need to hold the keys.
Actori holds every downstream credential — your AWS keys, Snowflake passwords, GitHub/Slack tokens, SSH keys — and makes the call itself. Your agents get results, not credentials.
- ✓Connector credentials are AES-256 encrypted at rest.
Identity & access
- ✓Every agent has its own identity — a per-agent signed token and least-privilege grants. Revocable.
- ✓Admin sessions use signed tokens with pinned signing algorithms.
- ✓SSO for admin login: OIDC and SAML, configurable per tenant.
- ✓Role-based and attribute-based access control, enforced on every action before it dispatches.
Deployment & isolation
Shared infrastructure in Actori’s cloud (US region). Fastest onboarding; tenant isolation is fail-closed.
For enterprises that require it, Actori runs your instance in an isolated cloud account — same platform, no shared infrastructure.
Auditability
- ✓Actions are recorded and the records are written server-side at the gate, not by the agent — an agent can’t fabricate or erase its own trail.
- ✓The trail is exportable.
Data handling & privacy
- ✓Actori is a governance layer, not a model provider — it does not train any model on your data.
- ✓Optional AI-assisted features: when you enable them, requests are sent to the LLM provider you select (Anthropic, OpenAI, Google, or Mistral) using your own API key. These features are off by default.
- ✓The following are configured by you, with your own credentials, and are not Actori subprocessors: your connectors, your notification channels (SMTP email / Slack), and — if enabled — the LLM provider above.
- ✓Where your data lives: Actori’s cloud (US region).
- ✓Subprocessors (parties that may process customer data on our behalf):
- –Amazon Web Services (AWS) — cloud infrastructure and hosting.
- –WorkOS — authentication and single sign-on.
- –Google — sign-in provider.
Audit log retention. Audit logs are retained for a minimum of 90 days; extended retention is available on higher-tier plans.
Data deletion. Following deactivation of your account, and unless prohibited by law, Actori will delete your Customer Data. We may retain data as needed to fulfill contractual obligations, comply with legal requirements, resolve disputes, and enforce agreements.
Security & your review
Actori is early-stage and does not hold formal certifications (SOC 2 / ISO 27001) yet. Here’s how we protect your data and support your security team:
- ✓We’ll complete your security questionnaire and walk your team through our architecture.
- ✓Report issues: security@actori.ai
Reliability
Availability. Production runs on a high-availability architecture, with multi-zone redundancy across the database and application tier.
We don’t publish a contractual uptime figure at this stage; a formal SLA is available as part of an Enterprise agreement.
Have a security question, questionnaire, or issue to report?
security@actori.ai