Security

Zero data plane by design.

AgentGuard Spend runs in process. Governed provider traffic goes directly from your application to the provider you selected, without an AgentGuard inference proxy. Policies and signing private keys stay in the SDK runtime. The browser verifier checks pasted decision receipts locally without becoming part of the provider call path.

Receipt verification

When signing keys and a decision-log store are configured, signed entries can be checked with Ed25519 signature verification and hash-chain validation. See the product boundary in the legal FAQ.

Infrastructure notes

Hosted endpoints are used for account, license, and optional telemetry workflows. AI calls and policy enforcement remain customer to provider.