WorkStudioLabPeopleInsights
Security posture

Your data stays where it lives.

RDLB Agentic operates beside your enterprise systems, never inside them. A sovereign runtime, read-only connectors, audit-grade logs, and a written policy library your security team can review before a single connector is opened.

11 policies, versionedReleased under NDALast reviewed September 2026
01 — What we assert, and what backs it

Every claim has a document behind it.

Nothing on this page is asserted without something a reviewer can be sent. The right-hand column names the artefact. All of them are released to your security team during review.

Runtime isolation

The agent runtime is separate from client production systems.

Verify · Request the runtime topology diagram; confirm no inbound path from runtime to your network.

Information Security Policy §4

Connector scope

Read-only, scoped per agent, revocable by the client at any time.

Verify · Issue a scoped credential, then revoke it mid-engagement and confirm the agent fails closed.

Sub-processor Inventory & Register

Write-back gate

No write to a client system without a named human approval.

Verify · Ask for an export of approvals for any period; every write should map to an approver.

AI Governance Framework §2

Breach history

Attested in writing and released with the document set under NDA.

Verify · Read the attestation and check its signature date against the engagement date.

Information Security Breach History

Model terms

Deployer of third-party models under no-training terms.

Verify · Ask which providers are in scope and request the corresponding no-training terms.

AI Governance Framework §5

Log retention

Every prompt, output and decision is versioned and exportable.

Verify · Request a log export for a date you choose and reconcile it against work you saw delivered.

Change Management Procedure

02 — The four pillars

Four pillars. No exceptions.

01

Sovereign environment

The agent runtime is isolated from your production systems. Agents request what they need through audited, scoped connectors, never through direct database access.

02

Read-only connectors

Scoped, audited, revocable. Agents never write back to enterprise systems without an explicit human gate. Every connector is owned by you, configurable by you, removable by you.

03

Auditable

Every prompt, output, and decision is versioned and exportable. Full action logs you can audit on demand. Nothing the system does is opaque to the buyer.

04

Model-agnostic

Claude, GPT, Gemini, Mistral. Models swap. The brand layer of voice, business logic, and decision rules does not. The work compounds; the dependency on any single vendor does not.

03 — The flow

A bridge, not a share.

Your data is read across a scoped, audited bridge into an isolated runtime. Anything that writes back to your systems waits for an explicit human gate.

Source

01

Your enterprise

CRM, ERP, data warehouse. Records and internal IP. Nothing is copied out of it.

Control · Access is scoped and issued by you

Read-only

02

The bridge

API, scoped per agent. Read-only, revocable, fully logged. Credentials are yours and stay yours.

Control · Read-only by construction; revocable at any time

Runtime

03

RDLB Agentic

Isolated agent runtime. Versioned prompts, full action logs, exportable on demand.

Control · Write-back blocked pending named human approval

Write-back requires an explicit human gate

04 — Where the edges are

What the system will not do.

Every line below is the direct inverse of a control on this page. A posture that only lists capabilities tells a reviewer nothing about where the boundaries sit, and the boundaries are what the review is for.

  • 01Agents do not hold standing credentials. Access is issued per engagement and revoked with it.
  • 02Agents do not write to a client system on their own authority. Every write waits on a named person.
  • 03No sensitive or regulated data is sent to a model provider.
  • 04No payment-card data and no Social Security numbers reach any sub-processor.
  • 05Nothing a client supplies is used to train a third-party model.
  • 06The policy library is not published. It is released to a named security team under NDA.
05 — Compliance and documented posture

Designed for the legal review.

EU AI ActDeployer, minimal-risk
GDPRProcessor terms
CCPA / CPRAService-provider terms
SOC 2-alignedCert on roadmap, Q3 2026
NIST 800-61 / 800-88IR and disposal
OneTrust-mappedVendor assessment

A documented posture, already written.

11 policies · v1.0 · released under NDA

01Information Security Policy
02AI Governance Framework
03Privacy & Data Protection Statement
04Sub-processor Inventory & Register
05Incident Response Plan
06Business Continuity & DR Plan
07Change Management Procedure
08Password & Authentication Policy
09Secure Disposal Procedure
10Breach History Attestation
11Information Security Breach History

The library is versioned and mapped to a OneTrust vendor assessment. Documents are released to your security team during review, not published here.

AI

We are a deployer of third-party models under no-training terms. No sensitive or regulated data goes to AI providers.

Data

Data minimization by default. No payment-card data or Social Security numbers reach any sub-processor.

Sub-processors

Every third party is registered, scoped, and reviewed on change. You are notified of material changes.

06 — CTO and CISO FAQ

The questions every technical reviewer asks.

Where does our data sit?+

In your sovereign environment. RDLB Agentic operates beside your enterprise database — never inside it. Read-only, scoped, revocable connectors. Every output versioned and exportable.

Who has access to our prompts and outputs?+

Only the named PM agent (Saturn) assigned to your engagement, the human approvers you designate, and our internal security team for audit. Prompt content is encrypted at rest. Not used to train any third-party model.

What happens if we want to leave?+

No lock-in, and no long contracts. Your data, your brand decisions, and every output stay yours and export on demand as JSON or CSV. You can pause or close the engagement on your terms, and your data leaves with you.

Are you using our data to train models?+

No. We are model-agnostic and route to frontier models via API. Your data is never sent to a model that uses it for training. Specific zero-retention configurations are available on request.

Where are the agents hosted?+

In an isolated runtime in a region you specify (US-East default, EU-West and AP-Southeast available). Agent runtime is single-tenant by default at the engagement tier.

What about model output safety?+

Every agent action is governed by approval gates. High-risk actions (financial, customer-facing communications, irreversible writes) require explicit human approval before execution. All gated actions are logged.

Can we audit a specific decision?+

Yes. Every output traces back to its prompt, its model, its source data, and its approver. Full audit trail exportable as JSON or CSV.

05 — For the technical review

Request the security posture brief.

Twelve-page PDF covering runtime architecture, connector design, model routing, identity inheritance, audit log format, data residency, and the standard DPA. Built for security and legal review, not marketing collateral.

We don't post this publicly. Requests go to a short queue; once approved, we email a short-TTL signed link that expires within 48 hours. Work email required.

A 30-minute call with the founder.

For CTOs and CISOs who want to walk the architecture before signing. Bring your hardest question. We will bring the runtime diagram, the audit log format, and the threat model.

Book a 30-minute strategy blueprint call