Security & Compliance
Last updated: 28 July 2026
TESSERACT is in private development. This page describes the security and compliance principles we build to, and the commitments we are working toward, rather than certifications we have yet completed.
TESSERACT builds security and governance for AI agents, and we hold our own systems to the same standard we ask customers to hold their agents to. Security and compliance are not features we add later; they are how the product is designed.
How we build
- Least privilege by default. Every internal system runs with the narrowest access needed, the same principle TESSERACT enforces for agents.
- Tamper-evident by design. Our evidence pipeline is hash-chained and independently witnessed, so records are verifiable rather than trusted on assertion.
- Data minimisation. We collect and retain only what a task requires, and we support deployment models that keep sensitive data inside a customer's own environment.
- Deployment choice for regulated estates. The control plane is designed to run as SaaS, hybrid, or fully on-premises, so data residency and isolation requirements can be met.
Compliance direction
As we move toward general availability, we are building the product and our internal controls to support the standards our regulated customers rely on, including SOC 2 and ISO 27001 alignment, GDPR and UK GDPR obligations, and the auditability that financial-services supervisors expect. We will publish our progress and independent attestations as they are completed, and we will not claim a certification before it is earned.
Reporting a vulnerability
Email [email protected] with enough detail to reproduce the issue. Please give us a reasonable time to investigate and remediate before any public disclosure.
Good-faith research
- Do not access, modify, or delete data that is not yours, and do not degrade service for others.
- Do not use social engineering, physical attacks, or denial-of-service techniques.
- Stay within the scope of our own systems and this website.
We will not pursue action against researchers who act in good faith and within these guidelines.
Our commitments
We aim to acknowledge reports promptly, keep you updated on progress, and credit researchers who wish to be named once an issue is resolved.