Security

Secure by design

Security of our agents and products is the top priority, and we build idemeum accordingly.

How idemeum stays compliant

An independent auditor tested how idemeum's security controls work over time, and you can request the full report.

AICPA SOC for Service Organizations seal

SOC 2 Type II

  • SOC 2 Type II certified
  • Audited by Prescient Security
  • AICPA Trust Services Criteria

How agents are secured

The LLM plans, deterministic tools act, and every step is checked and logged.

Security gate

Determines if the request is a legitimate support question and is safe to execute: catches ambiguity, prompt injection, or sensitive targets before any LLM call.

Plan and execute

Produces a complete plan that becomes a binding contract: the LLM cannot deviate from the plan, regardless of its own reasoning.

Reasoning guard

Validates the complete plan before execution: verifies that all tools are allowed for the plan, that their aggregate risk doesn't exceed the defined threshold, and that all tool prerequisites are met.

Access control

Administrators can define permitted tools, risk thresholds, and required diagnostic prerequisites per skill in the admin portal.

Execution guard

Enforces all tool checks at execution time and handles necessary user permission requests on the endpoint.

Deterministic tools

Every tool is implemented as deterministic TypeScript code, ensuring predictable, auditable execution with no hallucination risk.

Secret redaction

Every tool output is automatically sanitized for sensitive information before it reaches the LLM.

Chat audit trail

Every user conversation, tool run, consent, and output is captured in the cloud audit trail.

How Endpoint Control is secured

Phishing-resistant logins, keys in hardware, and checked devices.

Logins with MFA

Every login is multi-factor, using a combination of biometrics and certificates.

FIDO2 compliant

The idemeum mobile app implements MFA based on the modern FIDO2 standard.

Device recovery

When encryption keys are lost, recovery can be performed with the emergency key, or with approval from other technicians.

Device compliance

Validate device compliance with Android and iOS built-in security and signing certificates before granting access to the idemeum portal.

Hardware key storage

Mobile crypto keys are stored in StrongBox on Android and the Secure Enclave on iOS.

End-to-end encryption

Sensitive data is encrypted on your device with a key that never leaves it, so idemeum can't read your passwords or credentials.

How idemeum stays reliable

Built on AWS, redundant across zones, with a tested recovery plan.

AWS infrastructure

idemeum runs on AWS, with an architecture designed for business resilience.

Availability and failover

idemeum keeps your data safe with redundancy across multiple zones, comprehensive backups, and regularly tested disaster recovery and business continuity plans.

Service status

See idemeum's availability in real time on the status page.

See how idemeum is secured

Book a demo, and we'll walk your security team through the guardrails and controls.