Trust · detail
Security in detail.
The detail behind the Trust page, for security, risk and architecture reviewers.
Identity, access and isolation
- Identity. Sign in through your identity provider with OIDC single sign-on, and provision people with SCIM.
- Access control. Access is granted by role, to resources, and actions run under the identity of the person they are done for, not a shared account.
- Tenant isolation. Each customer runs its own instance, with tenant isolation inside it.
Where your data goes
Ceez runs inside the environment you deploy it to. This is what is kept, where, and what can leave.
| What | Where it lives | Leaves your environment? |
|---|---|---|
| Source records: ERP, CRM, documents | Your systems, under the permissions they already enforce | No. They are read in place, not bulk-copied. |
| Derived knowledge: definitions, lineage, the knowledge graph, rulings | Ceez Ground, in your deployment | No |
| Agent memory and sample values | Ceez Ground and Crew, in your deployment | No |
| Audit records | Your deployment, hash-chained | No |
| Model prompts and outputs | The model endpoint you configure: your provider under your keys, or a self-hosted model | Only to that endpoint. With a self-hosted model and no outside calls, nothing leaves. |
| Provider keys | Your infrastructure | No |
What agents can and cannot do
- Tools are granted per step. Before a step runs, Ceez works out exactly which skills, tools and knowledge it may use, and pins that set so it can be reconstructed later. By design, tool access is resolved before a step runs, not by what an agent reads.
- Limits stop actions. Spend limits and a blast-radius governor stop an action that is too large, and dual-control approvals send it to two named people.
- Autonomy is earned. A crew can run in shadow mode first. Autonomy is raised only after evaluations pass.
- Guardrails and a grounding check screen what an agent produces before it acts on it, and answers are traced to their source.
- Actions run as a person. Delegated identity means an action carries the permissions of the person it is done for, not a shared service account.
The audit trail
Every query, decision and API action is recorded and hash-chained to the one before it, so a change to an earlier entry is detectable and any run can be replayed. It is tamper-evident: it shows that a record was altered rather than preventing the alteration. The trail stays in your deployment, so an auditor can inspect it without asking us.
This is what a short run leaves behind. Each entry carries a hash of the one before it, so changing an earlier entry breaks every later hash.
| Time | Who | What | Entry hash | Previous |
|---|---|---|---|---|
| 09:02:11 | Crew · finance close | Read the sub-ledger, read-only | 7c1e…a904 | 0000…0000 |
| 09:02:40 | Crew · finance close | Matched three differences to their sources | a904…5be2 | 7c1e…a904 |
| 09:03:05 | Crew · finance close | Proposed a journal, over the single-approver limit | 5be2…d310 | a904…5be2 |
| 09:14:52 | Controller | Approved, 1 of 2 | d310…88f7 | 5be2…d310 |
| 09:20:07 | Finance director | Approved, 2 of 2 | 88f7…2c6a | d310…88f7 |
| 09:20:08 | Crew · finance close | Posted the journal | 2c6a…e1b3 | 88f7…2c6a |
Illustrative example · not customer data
Security reviews
We expect to be evaluated. During a walkthrough, our engineers walk your security and architecture teams through deployment, identity and access, data flows and the audit trail, and we respond to security questionnaires as part of your evaluation. Contact info@ceez.ai to start one.
Responsible disclosure
If you believe you have found a security vulnerability in Ceez or ceez.ai, please tell us. We appreciate reports from the security community and will work with you to resolve them.
How to report
Email info@ceez.ai with the subject line “Security report”. Please include:
- a description of the issue and where it occurs;
- steps to reproduce it, including any proof-of-concept;
- the impact you believe it has;
- how we can contact you for follow-up.
What you can expect from us
- We will acknowledge your report within three business days.
- We will keep you informed as we investigate and fix the issue.
- With your permission, we will credit you once the issue is resolved.
Good-faith research
We will not pursue legal action against research carried out in good faith under this policy. Please avoid privacy violations, data destruction and service disruption; only interact with accounts you own or have permission to test; do not access, modify or keep data that isn’t yours; and give us reasonable time to fix an issue before disclosing it publicly.
Out of scope: denial-of-service testing, social engineering or phishing of our staff, physical attacks, and automated scanner output without a demonstrated impact.
Architects: the technical overview and feature catalog. Machine-readable contact details are published at /.well-known/security.txt.