Skip to content

Security model

Provenant is designed to investigate production without touching it. It treats logs, code and incident text as untrusted input, and keeps humans in control of every change.

Commitment What it means
Read-only investigation Investigation identity is separate from remediation. Tools are allow-listed, bounded and read-only.
Human-approved remediation Only named, parameter-validated actions run — and only after explicit approval.
Secrets never stored Application records and prompts hold secret references, never credentials.
Redaction before AI PII, customer identifiers and credentials are redacted before any model sees them.
Tenant isolation Every record and connector call carries immutable tenant context.
Scoped repository access GitHub access is repository- and branch-scoped, read-only, with sensitive paths denied.
Your model, your choice Run local models, or a provider you approve. Every response records model provenance.
Compliance roadmap SOC 2 is on our roadmap.

The model never receives a shell, arbitrary Git, file system or database access, or the ability to write its own log or metric queries. It chooses from allow-listed investigation intents, and Provenant builds and runs the bounded query on the server.

The public API and its sandbox follow the same rules. See Sandbox and API keys.

For security questions, use the contact form on roveldi.ai and choose “Security question”.