Skip to content

Security · Trust

Self-hosted by design. Governance data stays in infrastructure you control.

Olivares AI integrates and secures the AI running in your enterprise — built around Claude — so it has to be secure first. It runs inside your own infrastructure, observes read-only, and records the map of access — not the data flowing through it. This page is how we prove it, honestly.

Data handling

What we touch, and what stays with you

The strongest privacy guarantee is architectural, not a certificate: Olivares governance data — inventory, access map, policy state and audit evidence — stays in infrastructure you control by default, and we never see it. Requests to hosted model providers, and any output or telemetry destinations you configure, go to the vendors you choose; Olivares itself has no mandatory calls home.

Runs in your infrastructure

Self-hosted on your own hosts, clusters or clouds — the control plane itself can run fully air-gapped, recording its access map with no egress of your data. Agents you govern still reach the APIs they call, such as a hosted model provider; only self-hostable models run fully offline. Self-hosted means your data does not leave your environment.

Edges, not payloads

It records access relationships — which agent can reach which resource, read versus read/write — not the query bodies, payloads or secrets that flow through them. What we don’t store, we can’t leak.

Secrets and PII redacted

Inputs that may carry secrets or personal data are redacted and secret-scanned before anything is written. More detail is something an operator has to consciously opt into.

Read-only observation

The collector observes; it never writes to your databases and never modifies your hosts. It reads identities such as a role or application name — not credential values. It is not a data sniffer.

No telemetry home

Secure by default means no phone-home: vendor telemetry is off unless you explicitly turn it on. Nothing about your estate is sent to us.

You control retention

Retention and purge are configurable, and in air-gapped deployments nothing ever leaves, full stop.

Vulnerability disclosure

Report a security issue

We welcome coordinated disclosure and act in good faith with researchers who do the same. Findings in the security model itself are explicitly welcome.

Report privately to

security@olivares.ai

Please don’t open a public issue, pull request or discussion for a suspected vulnerability. PGP is available on request before you send details.

What to expect

  • Acknowledgement within 3 business days
  • Initial assessment within 10 business days
  • Coordinated disclosure up to 90 days, sooner if a fix ships

Please don’t send

No real secrets, credentials or tokens (redact them), no customer or third-party personal data or production dumps, and no live exploitation of systems you don’t own. Describe sensitive impact rather than attaching it — we’ll arrange a secure channel.

Olivares AI is a pre-1.0 preview. There are no supported tagged versions yet; security fixes are applied to the main branch only.

Subprocessors

Who else processes data

This website uses no analytics, advertising or tracking subprocessors. It is a static site with self-hosted fonts, a strict same-origin Content-Security-Policy, and no cookies. It is served over a content delivery network, which handles only the connection metadata needed to deliver the page — we collect no personal data when you browse.

For the product itself: because Olivares AI is self-hosted on your own infrastructure, there is no vendor-side subprocessor for your data. It stays in your perimeter and we do not see it. Any future managed offering would publish its own subprocessor list; none is offered today.

Data processing

Data Processing Agreement (GDPR Art. 28)

A Data Processing Agreement is available on request for enterprise procurement. Because Olivares AI is self-hosted, in most deployments you remain the controller and processor of your own data within your own infrastructure; a DPA can still be executed to formalize responsibilities for a commercial relationship.

Compliance posture

Honest about where we are

Olivares AI is a pre-1.0 preview and is not certified under SOC 2, ISO/IEC 27001, the EU AI Act or any other framework, and no audit is in progress. We design the product to map to the controls those frameworks examine — audit logging, access control, integrity, encryption and change management — so that it is ready to be audited when the time comes. Formal certification (for example SOC 2 Type 2) is a later step the architecture is built to enable; it does not gate the first release.

Frameworks we design toward

  • SOC 2 / ISO 27001

    Control objectives we design toward — not certified, on the roadmap.

  • EU AI Act

    Designed to support its control and documentation expectations.

  • CSA MAESTRO

    A threat-modelling methodology we map against — not a certifiable standard.

  • OWASP agentic threats

    Mapped against the agentic threat and mitigation list.

  • CISA / NIST guidance

    Guidance, not a certifiable standard — design-toward, no conformance claim.

Where we describe alignment with external frameworks, this is a technical mapping, not a certification — and for standards that are not yet final it is a design-toward signal with no conformance claim.

Build integrity

  • Releases are cryptographically signed, ship with a software bill of materials, and carry build provenance.
  • A single, memory-safe static binary in minimal, hardened container images.
  • Minimal, pinned dependencies — no install scripts that run unverified code.
  • Dependency and secret scanning gate every change in CI.

These guarantees take effect at the first tagged release; the project is a pre-1.0 preview today.

Remediation targets

  • Critical 7 days
  • High 14 days
  • Medium 30 days
  • Low next scheduled release

Our committed remediation cadence, effective at the first tagged release. Actively-exploited vulnerabilities are treated as critical.

Trust questions

Where does my data go?

In the self-hosted edition, your data stays within your own infrastructure; Olivares AI does not receive it. The product records the map of access — not the payloads, secrets or personal data that move through it.

Are you SOC 2 or ISO 27001 certified?

Not yet. The product is designed to map to SOC 2 and ISO 27001 control objectives so it is ready to be audited, but formal certification is on the roadmap and has not been obtained. We will not claim a certification we do not hold.

How do I report a security vulnerability?

Email security@olivares.ai privately — please don’t open a public issue. Our full policy, including response timelines, is on this page and referenced from /.well-known/security.txt (RFC 9116). We acknowledge within three business days.

Do you offer a DPA?

Yes, a GDPR Article 28 Data Processing Agreement is available on request for enterprise procurement. Contact enterprise@olivares.ai.

Questions from your security or procurement team?

Report a vulnerability to our security contact, or reach out for procurement, a DPA or a security review.