Skip to content

Security & Compliance

The platform runs inside your boundary

Most AI security questions become simpler when the platform never leaves your infrastructure. This page sets out what MouRio does about deployment, identity, credentials, agent authority and evidence — in the order a review board usually asks.

  • Deployment boundary

    • Deployed into your own Azure, AWS or GCP subscription, VPC or data centre
    • Air-gapped and fully disconnected deployments supported
    • Data residency determined by where you install it, not by a vendor region list
    • No customer data is transmitted to MOURI Tech infrastructure
  • Identity & access

    • SSO via Entra ID, Okta or any OIDC provider
    • Space-scoped multi-tenancy — teams cannot see each other's agents, vaults or connectors
    • Role separation between platform administrators, builders and operators
    • Scoped, task-level tokens for agent actions rather than shared service accounts
  • Data & credentials

    • Connector credentials encrypted at rest before storage
    • Encryption keys held in your own key vault, under your rotation policy
    • Per-space isolation of documents, embeddings and retrieval indexes
    • Retention policies with automatic expiry of traces and audit records
  • Agent behaviour controls

    • Per-agent tool allow-lists enforced at execution time
    • Named human approvers required on designated actions
    • Value and rate limits on sensitive operations
    • Shadow mode so nothing executes until accuracy is measured
  • Audit evidence

    • Complete execution lineage for every run, replayable step by step
    • Every tool call recorded with arguments, result, cost and latency
    • Every policy evaluation and human intervention recorded against the run
    • Retrieved context and citations preserved with the decision they informed
  • Model & provider exposure

    • You choose which providers see anything — routing is per workload
    • Open-weight models hosted inside the boundary keep prompts in your network
    • Every run records which provider handled each call, so exposure is evidenced
    • Changing provider does not require rebuilding the agent or its policy

Review board

Security questions we are asked most

No. MouRio is installed into infrastructure you control, and the platform operates entirely within that boundary. Where we provide support, it is based on logs and evidence you choose to share with us, under the terms of your agreement.

Send us your security questionnaire.

We would rather answer it properly up front than discover a blocker three months into a programme. Our architects will work through it with your risk team.