CompanyAten Security joins Anthropic's Cyber Verification ProgramRead the post →

Security · Trust

Security at Aten.

Review our system boundaries, data-handling practices, and available security documentation. Report vulnerabilities directly to our security team.

  1. 01

    Identity boundary

    Establish the caller and available authority

  2. 02

    Policy boundary

    Evaluate the action against the organization’s rules

  3. 03

    Runtime control

    The integration applies the response before execution

  4. 04

    Decision evidence

    Retain the outcome and references for review

Identity, policy, and runtime boundaries separate a request from the protected action. Decision evidence connects the outcome to its controls.

System boundaries

Follow context from request to action.

The selected integration passes action context for evaluation. Aten returns a decision; the customer application remains responsible for handling that outcome and operating the target tool.

  1. Boundary 01

    Customer agent or application

  2. Boundary 02

    SDK or gateway boundary

  3. Boundary 03

    Policy decision service

  4. Boundary 04

    Customer tool or resource

Security principles

Controls should be understandable before deployment.

These principles guide product architecture and customer deployment discussions. Exact controls depend on the selected environment and agreement.

01

Explicit system boundaries

Document where action context enters, where decisions are returned, and which customer systems remain outside Aten’s control plane.

02

Minimized data handling

Scope collected context to what is needed for policy evaluation, operations, and agreed evidence requirements.

03

Least-privilege access

Separate service responsibilities and limit human and machine access to the resources required for each role.

04

Verifiable decision history

Preserve integrity data with decision records so later changes can be detected within the configured evidence system.

05

Configurable failure behavior

Let customers select workflow-appropriate behavior when a decision service is unavailable or required context is missing.

Data handling and isolation

Collect deliberately. Separate by tenant.

Data fields and retention are established for the integration rather than assumed across every deployment.

Action context

The integration sends the fields configured for evaluation, such as identity, task, session, tool, resource, and environment context.

Tenant boundaries

Tenant-scoped authorization and storage boundaries are designed to prevent one customer from accessing another customer’s data.

Retention and exports

Retention, evidence exports, and deletion requirements are confirmed for the selected deployment and customer agreement.

Identity and secrets

Use the least authority each component needs.

The integration model separates customer credentials and source permissions from the context used for policy decisions.

01

Identity and access

Administrative and service access is scoped by role, with customer integration permissions limited to their stated purpose.

02

Secrets

Secrets should be provided through supported secret-management paths and kept out of policy content and decision evidence.

03

Customer ownership

Customers retain responsibility for source identities, tool credentials, resource permissions, and how applications respond to decisions.

Decision integrity

Evidence designed to reveal changes.

Decision records can carry integrity data and linked references so modifications are detectable within the configured evidence path. Retention and export destinations are deployment choices.

Availability

Failure behavior belongs in policy.

Customers configure what happens when evaluation is unavailable or context is incomplete. A sensitive workflow may stop or seek approval, while a lower-risk workflow may use a defined fallback.

Security posture

Current practices, separated from target controls.

Verified assurance materials are shared through the Trust Center. Framework support and future assurance work are not presented here as completed attestations.

Current

Security program

current

Aten maintains documented security practices and reviews product controls as the platform evolves.

Responsible disclosure

current

Security researchers can report potential vulnerabilities directly to Aten for coordinated review.

Customer diligence

current

Current security documentation and available independent evidence can be requested through the Trust Center.

Designed to support

Framework support

Product controls are designed to support customer mappings to common security and AI-risk frameworks; applicability depends on deployment and customer configuration.

Ongoing assurance

Aten continues to mature its control environment and will publish verified assurance updates through the Trust Center.

Trust and disclosure

Review evidence. Report concerns directly.

Use the Trust Center for current security materials, or contact Aten through the responsible disclosure process.

Plan with clear boundaries

Review your security requirements with Aten.

Discuss system boundaries, data handling, failure behavior, and the assurance materials available for your evaluation.

Book a demoPartner with Aten

For technology, channel, federal delivery, and research partnerships.