Security
A control layer has to be the most trustworthy thing in the path
This page explains what Brakeproof sees, what it stores, how the evidence is protected, and what is still on the roadmap. Anything marked coming soon is not built yet.
No certifications claimed. Brakeproof is not SOC 2, ISO 27001 or ISO 42001 certified today. Brakeproof is in private preview.
Data handling
Metadata and redacted previews. Nothing more.
The principle from day one: never store customer data we don't need.
What the control plane receives
AvailableTo decide on a tool call, the proxy or SDK sends the metadata needed to apply your policies:
- agent, server, tool name and environment
- a short preview of the arguments, redacted before it is stored
- the risk score, the matched policy and the decision
The call itself is forwarded by the proxy straight to your system. Tool results are not sent to the control plane.
Redaction before storage
AvailableArgument previews are cleaned before they are written anywhere:
- email addresses become
[EMAIL] - card numbers that pass a Luhn check keep only the last four digits
- bearer tokens, API keys, GitHub and Slack tokens, AWS access key IDs and JWTs are masked
- fields named like
password,secret,api_keyortokenbecome[REDACTED] - the preview is truncated to 2 KB
Snapshots stay with you
AvailableBefore a risky call runs, the proxy takes the snapshot inside your environment (today, a consistent copy of a SQLite database next to the original). The control plane records only where the snapshot lives, so it can show it and request a restore.
If a snapshot cannot be taken, the call is blocked rather than run without a restore point.
Fail safe, by policy
Available- By default the proxy and SDK fail closed: risky calls are blocked while the control plane is unreachable.
- Each policy can choose fail open or fail closed. When in doubt, the proxy blocks.
- A bad API key always blocks, so a typo cannot silently switch the brakes off.
- A call that needs approval is never forwarded without one.
Brakeproof AI: AI advises, rules decide
Available- No AI call is on the decision path. Allow, pause and block are decided by your rules first.
- AI can raise a flag or recommend deny. It can never approve, lower a risk or change a policy.
- Only redacted data is sent, to your own Gemini, Claude or OpenAI key.
Red-team tests, run safely
Available- An admin must confirm they own or may test the target before every run. The consent is written to the ledger.
- Every run has a budget cap and a time limit, and is billed to your own AI key.
- The test worker only contacts your AI provider and your target.
- Attacks and replies are redacted and cut to 4 KB before storage. Target secrets are write-only and encrypted.
Evidence
A ledger that shows if anyone changed it
Every interception, decision, approval, policy change, snapshot and kill-switch event becomes an entry in a per-organisation, append-only hash chain.
Hash-chained ledger
AvailableEach entry stores the hash of the one before it: hash = sha256(prev_hash + canonical_json(entry)), starting from a fixed genesis value. Editing, removing or reordering any entry breaks every hash after it.
A verify endpoint recomputes the chain and reports the first bad index. The ledger can be exported as CSV or JSON for your own records.
Every 50 entries, and on every export, the server adds a checkpoint signed with its Ed25519 ledger key. The public key is published, so anyone holding an export can check the signature.
Signed decisions
BetaWith the mobile app, each approval or denial is signed on the device with an ECDSA P-256 key. The signature covers the approval, the decision and the time. The server verifies it against the registered device before the decision counts, and stores it in the ledger entry. Revoked devices cannot sign.
Credentials
AvailableAPI keys and session tokens are stored only as SHA-256 hashes and compared in constant time. Passwords are hashed with Argon2id.
Where it runs
Your agents in your cloud
Global customers need code and data to stay where their regulators expect it.
Deploy agents to your own cloud
BetaBrakeproof packages your agent with the guard built in and deploys it to Docker, Hugging Face Spaces or AWS ECS Fargate, in your own account. Your code, secrets and compute stay with you, and you pay your cloud provider directly.
We do not host your agents. If the deployed agent cannot reach the control plane, it fails closed.
Read-only security sensors
AvailableSensors only read. They never write to your systems:
- AWS through a read-only IAM role
- GitHub through a read-only token
- websites only on domains you prove you own
- mobile app files (APK, AAB or IPA) that you upload
Hosted regions: US, EU, Gulf
Coming soonHosted control planes in the US and EU first, then the Gulf, with region pinning on Enterprise.
Self-hosted control plane
Coming soonRun the control plane inside your own network, so metadata and keys never leave it. Part of Enterprise.
Security roadmap
What exists, and what doesn't yet
| Control | Status | Notes |
|---|---|---|
| Redacted argument previews (2 KB cap) | Available | Emails, card numbers, tokens, keys and secret fields masked before storage |
| Hash-chained evidence ledger + verify + CSV/JSON export | Available | Per organisation, append-only |
| Signed ledger checkpoints | Available | Ed25519, every 50 entries and on every export; the public key is published |
| Fail-closed defaults in proxy and SDK | Available | Per-policy fail mode when the control plane is unreachable |
| Snapshot before risky calls, restore | Available | SQLite today; Postgres rows, git refs and S3 objects coming soon |
| API keys and sessions stored as hashes | Available | SHA-256 with constant-time comparison; passwords with Argon2id |
| Signed mobile decisions, device revocation | Beta | Built; the iOS and Android apps are in testing |
| Roles: owner, admin, approver, viewer | Available | Every request is checked against the signed-in role |
| Brakeproof AI: advisory only, redacted input | Available | Never on the decision path; uses your own AI key |
| Red-team runs: consent, budget cap, redacted results | Available | Consent is recorded in the ledger; target secrets are write-only |
| Read-only security sensors | Available | AWS read-only role, GitHub token, verified domains, uploaded app files |
| Audit export mapped to SOC 2, ISO 42001, EU AI Act | Coming soon | Helps your audits; it is not a certification of us |
| Single sign-on (SSO) | Coming soon | Enterprise |
| Hosted regions: US, EU, Gulf; region pinning | Coming soon | Region pinning on Enterprise |
| Self-hosted control plane | Coming soon | Enterprise |
| Independent audit and certifications | Coming soon | Not started. We hold no certifications today |
A security contact and a vulnerability disclosure policy will be published before general availability.
Join the waitlist