Security & Compliance
Built for the work your CISO has to defend.
Bolt and Aeira are built to the security bar regulated industries demand, which means they work for any enterprise that takes governance seriously, not just the ones a regulator forces to. This page covers our architectural posture, the compliance regimes the platform is deployable for today, and our roadmap. Detailed security briefs and threat models are shared under NDA. An external penetration test runs in October 2026; its summary will be public and the full report available on request.
At a glance
The posture, summarized.
Identity-bound by design
No provider API keys in circulation
Encrypted & auditable
Forwards to your SIEM
Patent-pending architecture
Tamper-evident audit
Sealed into an Ed25519-signed Merkle chain.
- Agent turns and tool calls
- Human approvals
- Masking and authorization decisions
- Search
- Admin policy changes
- Security-relevant identity transitions sign-in, sign-out, session delegation, delegated-session revocation, session attach
- Privileged key and identity operations KMS rotation, crypto-shred, PII reveal, SCIM token issue and revoke
Managed policy
Governed by device policy too.
- macOS The desktop app reads the configuration profile your MDM pushes.
- Browser extension It reads managed policy on Chrome, Edge, Brave, Firefox and Safari.
- Windows The app reads Group Policy from the machine tree, and ships ADMX and ADML templates so the settings appear in the Group Policy Editor.
- One merge rule, documented precedence Device policy, your server policy and the built-in floor are reconciled by one merge rule, so two sources cannot quietly disagree.
- Per-user keys are excluded by design on both platforms A local user cannot forge managed policy for themselves.
Compliance Posture
What's deployable today, what's on the roadmap.
We use precise language about compliance: an architecture is "deployable" for a regime when it can be configured to satisfy that regime's technical requirements, but a formal certification is a separate process with a third-party auditor. Here's where we are honestly.
| Regime | Status | Notes |
|---|---|---|
| HIPAA | Architecture deployable | Self-hosted variants meet HIPAA technical safeguards. BAAs available on enterprise contracts during pilot evaluation. |
| SOX | Architecture deployable | Audit-trail responses, tamper-evident logging, and role-based controls support SOX IT general controls. Customer-specific scope reviewed during pilot. |
| ITAR / Export Control | Architecture deployable | Air-gapped Federated tier available. US-person-only access controls and data residency enforced via deployment configuration. |
| GDPR / UK GDPR | Architecture deployable | Per-person erasure with a receipt for Right to be Forgotten; per-tenant crypto-shred. EU + UK data residency via region-pinned deployments. |
| FCA / PRA (UK financial services) | Architecture deployable | Self-hosted posture supports SYSC 8 outsourcing, SS1/21 + PS21/3 operational resilience, SS1/23 third-party risk, and DP5/22 AI model risk. Customer remains the regulated entity; Sparcle ships software, the firm runs it. Architecture brief + DPA + third-party-register template under NDA. |
| DORA (EU financial services) | Architecture deployable | Self-hosted + BYO LLM avoids ICT third-party concentration risk. Exit-portable via Helm / Docker Compose. ICT incident logging + reporting hooks available. |
| Google CASA | Independently assessed | Assessed by TAC Security, an authorized CASA lab, against the 48 requirements Google requires before an application may hold restricted Gmail scopes. Scoped to Bolt's handling of Google user data, not a penetration test and not a SOC 2 substitute. Detail at /trust/independent-assessment. |
| SOC 2 Type II | Roadmap | Audit engagement planned. Honest framing: no formal certification yet. Aligned controls implemented; happy to share gap analysis under NDA. |
| FedRAMP Moderate | Roadmap | Federated tier targeted. Multi-quarter effort; we work with sponsoring agency partners during pilot. |
| ISO 27001 | Roadmap | Audit engagement on the path; controls aligned. NDA brief covers timeline. |
Deployment Models
Your data plane stays in your perimeter, always.
Self-Hosted (every Bolt tier, Aeira Dynamic / Enhanced)
Bring your own LLM (any tier)
Air-Gapped (Aeira Federated)
Available under NDA
Where the technical depth lives.
We deliberately don't publish implementation specifics on the public site. Below is what we share under a mutual NDA during pilot evaluation:
- Architecture brief: component-level diagrams of Bolt's runtime and Aeira's data plane, including the cache hierarchy, the priority engine's scoring model, and the security pipeline's specific layers
- Security posture documentation: threat model, encryption details, key management semantics, audit log format and retention
- Patent claim summaries: what the patent-pending architecture covers and how it maps to the runtime
- Penetration test report: an external firm tests Bolt in October 2026; once the report is issued, a summary is published on the trust page and the full report is available on request
- Compliance gap analysis: honest current-vs-target view for SOC 2, ISO 27001, FedRAMP
- Reference customer conversations: design partners willing to take a call about their experience
- Deployment runbook: Helm charts, Docker Compose, Kubernetes manifests, and the operational guides used during go-live
Take the next step.
Schedule a 30-minute call to walk through the architecture, request the security brief under NDA, or arrange a reference conversation with a design partner.