Security is the product.
Here is ours.
SolonGate secures other people's AI, which makes our own posture the first thing worth auditing. This page states 19 controls across four domains, the compliance work behind them, and where every document of record lives.
The controls, stated plainly
Grouped the way a security review asks for them. Each one is a written policy commitment, an architectural property, or a practice the product itself demonstrates.
Product security
Local-first enforcement
Security decisions are made on the user's device before execution; SolonGate is not a network proxy in the path of commands or AI requests.
Deterministic policy engine
ALLOW / DENY is decided by explicit policy against real payloads, not by a second model interpreting intent.
Tamper-evident audit trail
Every decision is written to an audit log designed to surface alteration.
Automated 90-day retention
Cloud audit records, captured content, and screenshots are deleted on an automated 90-day schedule.
Air-gapped self-hosting
The self-hosted edition runs with zero outbound dependencies and uses none of our cloud subprocessors.
Data privacy
No sale of Customer Content
Customer Content is never sold and never provided to data brokers.
No advertising use
Customer Content is never used for targeted or behavioral advertising or unrelated profiling.
No AI training on your data
Customer Content is never used to train general-purpose or proprietary AI models, and is never automatically submitted to third-party AI providers.
Public subprocessor list
Every third party that processes personal data on our behalf is disclosed, with its purpose and location.
Privacy rights with appeal
Access, deletion, correction, and portability requests are honored as described in the Privacy Policy, with a documented appeal path.
International transfer safeguards
Where restricted transfers occur, a legally recognized mechanism such as Standard Contractual Clauses is implemented.
Infrastructure security
Encryption in transit
Traffic between clients and SolonGate-hosted Services is protected with TLS.
Audited cloud providers
Cloud Services run on infrastructure providers that publish their own SOC 2 and ISO 27001 attestations.
Multi-factor authentication
MFA is supported on SolonGate accounts.
Security headers and hardening
Public surfaces ship with strict transport and content-security headers.
Organizational security
Least-privilege access
Access to Customer Content by SolonGate personnel is restricted to authorized personnel and permitted purposes.
Use limitations on personnel
Personnel may not use Customer Content for unrelated personal, advertising, or commercial purposes.
Chrome Web Store Limited Use
Browser-extension data use complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
Vulnerability reporting channel
A monitored channel accepts external vulnerability reports and responds to them.
Where your data is processed
The third parties that help run SolonGate Cloud. The self-hosted, air-gapped edition uses none of them.
Current as of September 3, 2026
| Name | Purpose | Location |
|---|---|---|
| Railway | Cloud hosting and infrastructure | United States |
| Turso | Database (libSQL / SQLite) | United States |
| Supabase | Authentication and storage | United States |
| Upstash | Rate limiting and caching (serverless Redis) | United States |
| Cloudflare | Object storage (R2) and content delivery | United States |
| GitHub | Authentication (OAuth sign-in) | United States |
| Anthropic | AI provider for user-initiated features (dashboard assistant, AI-assisted policy generation) | United States |
| Brevo | Transactional and product email | France |
| Resend | Transactional email (fallback delivery) | United States |
| Grafana Cloud | Monitoring and observability | United States |
| Cal.com | Demo scheduling | United States |
Documents of record
What reviewers ask first
What is the difference between Agent Security and Shadow AI?
Agent Security guards autonomous agents: it sits in front of your MCP servers and decides every tool call an agent fires, before it executes. Shadow AI guards the assistants your people already use in the browser — ChatGPT, Gemini, Copilot and dozens more — surfacing which ones are in use and what data is being handed to them. One policy engine, one audit trail, two very different kinds of AI.
How does Shadow AI detection work without reading my prompts?
The browser guard matches the surfaces themselves — the hostnames and upload paths of every known AI assistant, from a catalog the product maintains — not the content of a conversation. It records which assistant was used, when, and what files were handed over, and enforces your policy on those facts. What was said stays between your people and the assistant.
Does SolonGate require outbound internet access?
No. SolonGate is engineered for air-gapped and highly classified on-premise environments. It is deployed natively within your infrastructure. We have zero access to your data, your prompts, or your internal network traffic. Complete data sovereignty is maintained at all times.
What happens when an unauthorized action is detected?
The execution is immediately crushed. Depending on your organization’s custom Policy Engine configurations, SolonGate can silently drop the request, return a hard error to the agent, or route the specific action to a restricted queue for Human-in-the-Loop (HITL) approval.
Report a vulnerability
Found something in SolonGate itself? We want the report, however small. Email reproduction steps and we will respond, acknowledge, and credit you if you want the credit.
contact@solongate.com