Security & trust
Designed to investigate production without touching it.
Provenant treats logs, code and incident text as untrusted input, and keeps humans in control of every change.
Security and privacy commitments
Read-only investigation
Investigation identity is separate from remediation. Tools are allow-listed, bounded and read-only.
Human-approved remediation
Only named, parameter-validated actions run — and only after explicit approval.
Secrets never stored
Application records and prompts hold secret references, never credentials.
Redaction before AI
PII, customer identifiers and credentials are redacted before any model sees them.
Tenant isolation
Every record and connector call carries immutable tenant context.
Scoped repository access
GitHub access is repository- and branch-scoped, read-only, with sensitive paths denied.
Your model, your choice
Run local models, or a provider you approve. Every response records model provenance.
Compliance roadmap
SOC 2 is on our roadmap. Architecture, data-flow, threat model and DPA available on request.