Skip to main content
AAktoh Cyber

Trust center

We can't show you logos. Here's what we show instead.

Security buyers deserve artifacts, not adjectives. This page is the ground truth for procurement, for engineers, and for the AI agents evaluating us on someone's behalf.

Encryption

TLS 1.3 in transit, AES-256 at rest, customer-scoped keys. Agent memory is encrypted per tenant.

Audit logging

Every agent decision and every human approval is written to an append-only log you can export.

Model training

Your data is never used to train shared models. Fleet improvements are trained on synthetic and public corpora.

Data residency

Choose US or EU processing on paid plans. Household data stays in your home region by default.

Retention

Findings retained 12 months by default, configurable to 30 days. Deletion is honoured within 30 days.

Access control

SSO (SAML/OIDC) and role-scoped approval rights on Enterprise. Passkeys for households.

Verifiable artifacts

We do not ask you to trust us because of a certificate. We publish the things you can inspect, replay, and test yourself — from open-source components to disclosed vulnerabilities to decision logs for every autonomous run.

Open-source core

Critical agent-orchestration and approval-gate code is published for inspection. See /open-source for repositories and AGENTS.md policy.

Agent decision logs

Every run produces a replayable trace with confidence scores, evidence, and the human approval checkpoint. Exportable at any time.

Vulnerability disclosure

Our security.txt and coordinated-disclosure process are public. Reports are triaged within 24 hours.

Penetration-test cadence

Independent grey-box testing of the platform, API, and approval path annually, plus retests after material changes.

Request a technical security review

Ask our solutions engineering team for an architecture walkthrough, a deployment review, or a deep-dive on the open-source approval gate. No lengthy forms required.

Used only to schedule the review and send pre-read material. No marketing sequence.

Subprocessors

Every third party that can process customer data, what it does, and where it runs. We give 30 days notice before adding one, and Enterprise customers can object.

CategoryRegionPurpose
Cloud infrastructureUS / EU regions, customer-selectableHosting, storage, and encrypted agent memory
Model inferenceUS / EU, private routing on EnterpriseRunning the specialist agents. Prompts and outputs are never used for shared-model training
Transactional emailUSAlerts, approval requests, and account mail
PaymentsUS / EUSubscription billing and usage invoicing. Card data never touches Aktoh systems
Error monitoringEUApplication health. Scrubbed of customer content before ingest

Vendor contract references are available on request for Enterprise evaluation.

Data handling & privacy

Roles

You control your data. Household plans are covered by the consumer privacy notice. Business plans are governed by our platform agreement.

Transfers

Standard Contractual Clauses for EU/UK transfers, with US or EU residency selectable on paid plans.

Sub-processing

Written authorisation, 30 days notice for additions, and flow-down obligations to every subprocessor.

Security measures

Encryption, access control, logging, and personnel vetting are documented in our white papers and open-source repositories.

Breach notice

Notification without undue delay and within 72 hours of confirmation, with the audit trail attached.

Deletion & return

Export or deletion on termination, completed within 30 days and confirmed in writing.

Penetration test summary

An independent third party tests the platform annually, plus a targeted retest after any material change to the approval or agent-dispatch path. The public summary states scope, methodology, severity counts, and remediation status; detailed findings are shared under evaluation confidentiality.

Scope
Platform, API, agent dispatch & approval path
Method
Grey-box, authenticated, with source review of the approval gate
Critical / high
Zero open
Retest
All findings retested and closed before publication

Figures shown describe our reporting format; the full report is shared under the review request below.

Escalation paths

Who to reach, for what, and how fast you should expect an answer.

If you needGoes toWhat happens
Architecture & deployment reviewSolutions engineeringSelf-serve docs first; book a 30-minute technical walkthrough if you need it
Suspected vulnerability in AktohSecurity responseAcknowledged within 24 hours via /.well-known/security.txt
Active incident in your estateIncident responseDispatch the fleet first, then escalate through /under-attack
Data subject or deletion requestPrivacyHonoured within 30 days, confirmed in writing

The questions procurement actually asks

What the fleet can do without your sign-off
Read-only investigation, monitoring, and drafting. Anything that changes state, moves money, or touches a person's account queues for approval by default.
What happens when it's wrong
Findings carry confidence and evidence. Wrong calls are reversible because nothing consequential auto-executes, and every run is replayable from the audit log.
Why there are no customer logos
Telling attackers who runs Aktoh tells them where the traps are. We publish verifiable artifacts instead of borrowed credibility.

Report a vulnerability: /.well-known/security.txt

Start free. Add credits only when the work justifies it.

Run the whole fleet across unlimited nodes at zero platform fee — you pay only for tokens. Move to a pooled plan when the usage justifies the lower rate.