SolonGate Trust Center
solongate.com →
Overview

Security is the product.
Here is ours.

SolonGate secures other people's AI, which makes our own posture the first thing worth auditing. This page states 19 controls across four domains, the compliance work behind them, and where every document of record lives.

SOC 2 Type II In preparation
GDPR Aligned
UK GDPR Aligned
CWS Limited Use Compliant
01 · Controls

The controls, stated plainly

Grouped the way a security review asks for them. Each one is a written policy commitment, an architectural property, or a practice the product itself demonstrates.

Product security

  • Local-first enforcement

    Security decisions are made on the user's device before execution; SolonGate is not a network proxy in the path of commands or AI requests.

  • Deterministic policy engine

    ALLOW / DENY is decided by explicit policy against real payloads, not by a second model interpreting intent.

  • Tamper-evident audit trail

    Every decision is written to an audit log designed to surface alteration.

  • Automated 90-day retention

    Cloud audit records, captured content, and screenshots are deleted on an automated 90-day schedule.

  • Air-gapped self-hosting

    The self-hosted edition runs with zero outbound dependencies and uses none of our cloud subprocessors.

Data privacy

  • No sale of Customer Content

    Customer Content is never sold and never provided to data brokers.

  • No advertising use

    Customer Content is never used for targeted or behavioral advertising or unrelated profiling.

  • No AI training on your data

    Customer Content is never used to train general-purpose or proprietary AI models, and is never automatically submitted to third-party AI providers.

  • Public subprocessor list

    Every third party that processes personal data on our behalf is disclosed, with its purpose and location.

  • Privacy rights with appeal

    Access, deletion, correction, and portability requests are honored as described in the Privacy Policy, with a documented appeal path.

  • International transfer safeguards

    Where restricted transfers occur, a legally recognized mechanism such as Standard Contractual Clauses is implemented.

Infrastructure security

  • Encryption in transit

    Traffic between clients and SolonGate-hosted Services is protected with TLS.

  • Audited cloud providers

    Cloud Services run on infrastructure providers that publish their own SOC 2 and ISO 27001 attestations.

  • Multi-factor authentication

    MFA is supported on SolonGate accounts.

  • Security headers and hardening

    Public surfaces ship with strict transport and content-security headers.

Organizational security

  • Least-privilege access

    Access to Customer Content by SolonGate personnel is restricted to authorized personnel and permitted purposes.

  • Use limitations on personnel

    Personnel may not use Customer Content for unrelated personal, advertising, or commercial purposes.

  • Chrome Web Store Limited Use

    Browser-extension data use complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

  • Vulnerability reporting channel

    A monitored channel accepts external vulnerability reports and responds to them.

02 · Subprocessors

Where your data is processed

The third parties that help run SolonGate Cloud. The self-hosted, air-gapped edition uses none of them.

Current as of September 3, 2026

NamePurposeLocation
RailwayCloud hosting and infrastructureUnited States
TursoDatabase (libSQL / SQLite)United States
SupabaseAuthentication and storageUnited States
UpstashRate limiting and caching (serverless Redis)United States
CloudflareObject storage (R2) and content deliveryUnited States
GitHubAuthentication (OAuth sign-in)United States
AnthropicAI provider for user-initiated features (dashboard assistant, AI-assisted policy generation)United States
BrevoTransactional and product emailFrance
ResendTransactional email (fallback delivery)United States
Grafana CloudMonitoring and observabilityUnited States
Cal.comDemo schedulingUnited States
03 · Documents

Documents of record

04 · FAQ

What reviewers ask first

What is the difference between Agent Security and Shadow AI?

Agent Security guards autonomous agents: it sits in front of your MCP servers and decides every tool call an agent fires, before it executes. Shadow AI guards the assistants your people already use in the browser — ChatGPT, Gemini, Copilot and dozens more — surfacing which ones are in use and what data is being handed to them. One policy engine, one audit trail, two very different kinds of AI.

How does Shadow AI detection work without reading my prompts?

The browser guard matches the surfaces themselves — the hostnames and upload paths of every known AI assistant, from a catalog the product maintains — not the content of a conversation. It records which assistant was used, when, and what files were handed over, and enforces your policy on those facts. What was said stays between your people and the assistant.

Does SolonGate require outbound internet access?

No. SolonGate is engineered for air-gapped and highly classified on-premise environments. It is deployed natively within your infrastructure. We have zero access to your data, your prompts, or your internal network traffic. Complete data sovereignty is maintained at all times.

What happens when an unauthorized action is detected?

The execution is immediately crushed. Depending on your organization’s custom Policy Engine configurations, SolonGate can silently drop the request, return a hard error to the agent, or route the specific action to a restricted queue for Human-in-the-Loop (HITL) approval.

05 · Report

Report a vulnerability

Found something in SolonGate itself? We want the report, however small. Email reproduction steps and we will respond, acknowledge, and credit you if you want the credit.

contact@solongate.com