Skip to content

Security & trust

Designed to investigate production without touching it.

Provenant treats logs, code and incident text as untrusted input, and keeps humans in control of every change.

Security and privacy commitments

  1. Read-only investigation

    Investigation identity is separate from remediation. Tools are allow-listed, bounded and read-only.

  2. Human-approved remediation

    Only named, parameter-validated actions run — and only after explicit approval.

  3. Secrets never stored

    Application records and prompts hold secret references, never credentials.

  4. Redaction before AI

    PII, customer identifiers and credentials are redacted before any model sees them.

  5. Tenant isolation

    Every record and connector call carries immutable tenant context.

  6. Scoped repository access

    GitHub access is repository- and branch-scoped, read-only, with sensitive paths denied.

  7. Your model, your choice

    Run local models, or a provider you approve. Every response records model provenance.

  8. Compliance roadmap

    SOC 2 is on our roadmap. Architecture, data-flow, threat model and DPA available on request.

Give every engineer your best engineer’s context.