Secure by design
Security of our agents and products is the top priority, and we build idemeum accordingly.
How idemeum stays compliant
An independent auditor tested how idemeum's security controls work over time, and you can request the full report.

SOC 2 Type II
- SOC 2 Type II certified
- Audited by Prescient Security
- AICPA Trust Services Criteria
How agents are secured
The LLM plans, deterministic tools act, and every step is checked and logged.
Security gate
Determines if the request is a legitimate support question and is safe to execute: catches ambiguity, prompt injection, or sensitive targets before any LLM call.
Plan and execute
Produces a complete plan that becomes a binding contract: the LLM cannot deviate from the plan, regardless of its own reasoning.
Reasoning guard
Validates the complete plan before execution: verifies that all tools are allowed for the plan, that their aggregate risk doesn't exceed the defined threshold, and that all tool prerequisites are met.
Access control
Administrators can define permitted tools, risk thresholds, and required diagnostic prerequisites per skill in the admin portal.
Execution guard
Enforces all tool checks at execution time and handles necessary user permission requests on the endpoint.
Deterministic tools
Every tool is implemented as deterministic TypeScript code, ensuring predictable, auditable execution with no hallucination risk.
Secret redaction
Every tool output is automatically sanitized for sensitive information before it reaches the LLM.
Chat audit trail
Every user conversation, tool run, consent, and output is captured in the cloud audit trail.
How Endpoint Control is secured
Phishing-resistant logins, keys in hardware, and checked devices.
Logins with MFA
Every login is multi-factor, using a combination of biometrics and certificates.
FIDO2 compliant
The idemeum mobile app implements MFA based on the modern FIDO2 standard.
Device recovery
When encryption keys are lost, recovery can be performed with the emergency key, or with approval from other technicians.
Device compliance
Validate device compliance with Android and iOS built-in security and signing certificates before granting access to the idemeum portal.
Hardware key storage
Mobile crypto keys are stored in StrongBox on Android and the Secure Enclave on iOS.
End-to-end encryption
Sensitive data is encrypted on your device with a key that never leaves it, so idemeum can't read your passwords or credentials.
How idemeum stays reliable
Built on AWS, redundant across zones, with a tested recovery plan.
AWS infrastructure
idemeum runs on AWS, with an architecture designed for business resilience.
Availability and failover
idemeum keeps your data safe with redundancy across multiple zones, comprehensive backups, and regularly tested disaster recovery and business continuity plans.
Service status
See idemeum's availability in real time on the status page.
See how idemeum is secured
Book a demo, and we'll walk your security team through the guardrails and controls.