TESSERACT

Security & Compliance

Last updated: 28 July 2026
TESSERACT is in private development with a small number of design partners. This page sets out the security principles the product is engineered to, how we protect customer data, and the compliance path we are executing. Where a control is in place today we say so. Where it is a commitment we are working toward, we say that too. We will not claim a certification before it is earned.

We build the control plane that lets an enterprise see, govern, and prove what its AI agents are allowed to do. A company that sells governance has to be governed at least as well as the systems it protects. So we hold our own engineering, infrastructure, and data handling to the standard we ask customers to hold their agents to, and we treat security as a property of the design rather than a layer added at the end.

How the product is engineered

Product security

How we handle data

Data protection and privacy

The standards we build to

Compliance and regulatory alignment

Our customers operate in regulated industries, and increasingly the agents they deploy fall under new supervision of their own. We are building the product and our internal control environment to meet the frameworks those customers and their regulators rely on.

We will publish attestations and reports as they are completed. Until then we are precise about what is in place and what is in progress, and we are glad to walk security and compliance teams through our current posture under NDA.

How we work together

Shared responsibility

Security is a shared responsibility. We are accountable for the security of the platform, and we give customers the controls, evidence, and documentation to operate it safely inside their own environment. We respond to security questionnaires and vendor due-diligence reviews, and every design-partner engagement begins with a review of exactly these questions, not a slide that waves them away.

Reporting a security concern

If you believe you have found a vulnerability in our product or systems, we want to hear from you, and we extend clear protections to good-faith researchers. Our disclosure process, scope, and safe-harbour commitments live on a dedicated page.

Read our Responsible Disclosure policy, or for any other security or compliance question, or to request our current documentation, contact [email protected].