Security due diligence

What your clients' security teams will ask, answered.

Partners stake their client relationships on the platform underneath them. This page is for the due-diligence review.

Deployment boundary

Start with where the operating layer runs.

Deployment options are reviewed against the partner solution, the client's environment and the required operating boundary. Scope and availability are agreed during technical review.

SmoothOperator.ai cloud

A managed deployment boundary scoped to the agreed solution.

Your cloud

The operating layer deployed inside the partner-controlled cloud boundary.

Client on-premises

The solution runs inside the customer's own infrastructure boundary.

Air-gapped environment

A disconnected deployment pattern considered during technical review.

No deployment pattern is presented as a one-size-fits-all configuration. The exact boundary is part of the technical review.

Verified control areas

Controls that are part of the operating architecture.

Data boundary

Client knowledge stays scoped to the deployment.

Collections separate each client's context from partner templates and rules. Workflows receive only the approved collections and operating context.

Access control

Access is set at the collection, agent and workflow level.

Each workflow can be scoped to the context and tools it is allowed to use. Access design is reviewed for the specific deployment.

Execution controls

Workflow boundaries are enforced while agents run.

Execution controls define what a workflow may and may not do, so operating boundaries are part of the runtime rather than a policy applied after the fact.

Traceability

The execution path can be reviewed.

Inputs, tool calls, agent steps, sources and outputs are traceable, preserving the material needed to review how a result was produced.

Model and tool access

Provider credentials remain part of the controlled configuration.

Model and tool access is configured for the deployment, including customer-held model keys and authenticated, allowlisted tool connections.

Deployment-specific review

Review the controls for the solution you are taking to market.

Bring your proposed solution and deployment context to a technical due-diligence discussion. We can review the relevant controls together rather than substituting a generic assurance badge for architecture review.

  • Deployment and network boundary
  • Collection, agent and workflow access model
  • Execution-control design
  • Inputs, tool calls, sources and output trace
  • Model credentials and tool authentication

Technical due diligence

Review the controls against your client environment.

Tell us about the solution, deployment boundary and review requirements. We will scope the security conversation to that environment.

Discuss technical due diligence