01
Explicit system boundaries
Document where action context enters, where decisions are returned, and which customer systems remain outside Aten’s control plane.
Security · Trust
Review our system boundaries, data-handling practices, and available security documentation. Report vulnerabilities directly to our security team.
01
Identity boundary
Establish the caller and available authority
02
Policy boundary
Evaluate the action against the organization’s rules
03
Runtime control
The integration applies the response before execution
04
Decision evidence
Retain the outcome and references for review
System boundaries
The selected integration passes action context for evaluation. Aten returns a decision; the customer application remains responsible for handling that outcome and operating the target tool.
Customer agent or application
SDK or gateway boundary
Policy decision service
Customer tool or resource
Security principles
These principles guide product architecture and customer deployment discussions. Exact controls depend on the selected environment and agreement.
01
Document where action context enters, where decisions are returned, and which customer systems remain outside Aten’s control plane.
02
Scope collected context to what is needed for policy evaluation, operations, and agreed evidence requirements.
03
Separate service responsibilities and limit human and machine access to the resources required for each role.
04
Preserve integrity data with decision records so later changes can be detected within the configured evidence system.
05
Let customers select workflow-appropriate behavior when a decision service is unavailable or required context is missing.
Data handling and isolation
Data fields and retention are established for the integration rather than assumed across every deployment.
The integration sends the fields configured for evaluation, such as identity, task, session, tool, resource, and environment context.
Tenant-scoped authorization and storage boundaries are designed to prevent one customer from accessing another customer’s data.
Retention, evidence exports, and deletion requirements are confirmed for the selected deployment and customer agreement.
Identity and secrets
The integration model separates customer credentials and source permissions from the context used for policy decisions.
01
Administrative and service access is scoped by role, with customer integration permissions limited to their stated purpose.
02
Secrets should be provided through supported secret-management paths and kept out of policy content and decision evidence.
03
Customers retain responsibility for source identities, tool credentials, resource permissions, and how applications respond to decisions.
Decision integrity
Decision records can carry integrity data and linked references so modifications are detectable within the configured evidence path. Retention and export destinations are deployment choices.
Availability
Customers configure what happens when evaluation is unavailable or context is incomplete. A sensitive workflow may stop or seek approval, while a lower-risk workflow may use a defined fallback.
Security posture
Verified assurance materials are shared through the Trust Center. Framework support and future assurance work are not presented here as completed attestations.
Current
Aten maintains documented security practices and reviews product controls as the platform evolves.
Security researchers can report potential vulnerabilities directly to Aten for coordinated review.
Current security documentation and available independent evidence can be requested through the Trust Center.
Designed to support
Product controls are designed to support customer mappings to common security and AI-risk frameworks; applicability depends on deployment and customer configuration.
Aten continues to mature its control environment and will publish verified assurance updates through the Trust Center.
Trust and disclosure
Use the Trust Center for current security materials, or contact Aten through the responsible disclosure process.
Plan with clear boundaries
Discuss system boundaries, data handling, failure behavior, and the assurance materials available for your evaluation.