Skip to content
Brakeproof

Security

A control layer has to be the most trustworthy thing in the path

This page explains what Brakeproof sees, what it stores, how the evidence is protected, and what is still on the roadmap. Anything marked coming soon is not built yet.

No certifications claimed. Brakeproof is not SOC 2, ISO 27001 or ISO 42001 certified today. Brakeproof is in private preview.

Data handling

Metadata and redacted previews. Nothing more.

The principle from day one: never store customer data we don't need.

What the control plane receives

Available

To decide on a tool call, the proxy or SDK sends the metadata needed to apply your policies:

  • agent, server, tool name and environment
  • a short preview of the arguments, redacted before it is stored
  • the risk score, the matched policy and the decision

The call itself is forwarded by the proxy straight to your system. Tool results are not sent to the control plane.

Redaction before storage

Available

Argument previews are cleaned before they are written anywhere:

  • email addresses become [EMAIL]
  • card numbers that pass a Luhn check keep only the last four digits
  • bearer tokens, API keys, GitHub and Slack tokens, AWS access key IDs and JWTs are masked
  • fields named like password, secret, api_key or token become [REDACTED]
  • the preview is truncated to 2 KB

Snapshots stay with you

Available

Before a risky call runs, the proxy takes the snapshot inside your environment (today, a consistent copy of a SQLite database next to the original). The control plane records only where the snapshot lives, so it can show it and request a restore.

If a snapshot cannot be taken, the call is blocked rather than run without a restore point.

Fail safe, by policy

Available
  • By default the proxy and SDK fail closed: risky calls are blocked while the control plane is unreachable.
  • Each policy can choose fail open or fail closed. When in doubt, the proxy blocks.
  • A bad API key always blocks, so a typo cannot silently switch the brakes off.
  • A call that needs approval is never forwarded without one.

Brakeproof AI: AI advises, rules decide

Available
  • No AI call is on the decision path. Allow, pause and block are decided by your rules first.
  • AI can raise a flag or recommend deny. It can never approve, lower a risk or change a policy.
  • Only redacted data is sent, to your own Gemini, Claude or OpenAI key.

Red-team tests, run safely

Available
  • An admin must confirm they own or may test the target before every run. The consent is written to the ledger.
  • Every run has a budget cap and a time limit, and is billed to your own AI key.
  • The test worker only contacts your AI provider and your target.
  • Attacks and replies are redacted and cut to 4 KB before storage. Target secrets are write-only and encrypted.

Evidence

A ledger that shows if anyone changed it

Every interception, decision, approval, policy change, snapshot and kill-switch event becomes an entry in a per-organisation, append-only hash chain.

Hash-chained ledger

Available

Each entry stores the hash of the one before it: hash = sha256(prev_hash + canonical_json(entry)), starting from a fixed genesis value. Editing, removing or reordering any entry breaks every hash after it.

A verify endpoint recomputes the chain and reports the first bad index. The ledger can be exported as CSV or JSON for your own records.

Every 50 entries, and on every export, the server adds a checkpoint signed with its Ed25519 ledger key. The public key is published, so anyone holding an export can check the signature.

Signed decisions

Beta

With the mobile app, each approval or denial is signed on the device with an ECDSA P-256 key. The signature covers the approval, the decision and the time. The server verifies it against the registered device before the decision counts, and stores it in the ledger entry. Revoked devices cannot sign.

Credentials

Available

API keys and session tokens are stored only as SHA-256 hashes and compared in constant time. Passwords are hashed with Argon2id.

Where it runs

Your agents in your cloud

Global customers need code and data to stay where their regulators expect it.

Deploy agents to your own cloud

Beta

Brakeproof packages your agent with the guard built in and deploys it to Docker, Hugging Face Spaces or AWS ECS Fargate, in your own account. Your code, secrets and compute stay with you, and you pay your cloud provider directly.

We do not host your agents. If the deployed agent cannot reach the control plane, it fails closed.

Read-only security sensors

Available

Sensors only read. They never write to your systems:

  • AWS through a read-only IAM role
  • GitHub through a read-only token
  • websites only on domains you prove you own
  • mobile app files (APK, AAB or IPA) that you upload

Hosted regions: US, EU, Gulf

Coming soon

Hosted control planes in the US and EU first, then the Gulf, with region pinning on Enterprise.

Self-hosted control plane

Coming soon

Run the control plane inside your own network, so metadata and keys never leave it. Part of Enterprise.

Security roadmap

What exists, and what doesn't yet

Security features and their status
ControlStatusNotes
Redacted argument previews (2 KB cap)AvailableEmails, card numbers, tokens, keys and secret fields masked before storage
Hash-chained evidence ledger + verify + CSV/JSON exportAvailablePer organisation, append-only
Signed ledger checkpointsAvailableEd25519, every 50 entries and on every export; the public key is published
Fail-closed defaults in proxy and SDKAvailablePer-policy fail mode when the control plane is unreachable
Snapshot before risky calls, restoreAvailableSQLite today; Postgres rows, git refs and S3 objects coming soon
API keys and sessions stored as hashesAvailableSHA-256 with constant-time comparison; passwords with Argon2id
Signed mobile decisions, device revocationBetaBuilt; the iOS and Android apps are in testing
Roles: owner, admin, approver, viewerAvailableEvery request is checked against the signed-in role
Brakeproof AI: advisory only, redacted inputAvailableNever on the decision path; uses your own AI key
Red-team runs: consent, budget cap, redacted resultsAvailableConsent is recorded in the ledger; target secrets are write-only
Read-only security sensorsAvailableAWS read-only role, GitHub token, verified domains, uploaded app files
Audit export mapped to SOC 2, ISO 42001, EU AI ActComing soonHelps your audits; it is not a certification of us
Single sign-on (SSO)Coming soonEnterprise
Hosted regions: US, EU, Gulf; region pinningComing soonRegion pinning on Enterprise
Self-hosted control planeComing soonEnterprise
Independent audit and certificationsComing soonNot started. We hold no certifications today

A security contact and a vulnerability disclosure policy will be published before general availability.

Join the waitlist