Security

Enterprise security posture.

A2AC is built for governed AI workflows on Google Cloud. Current controls, preview controls, and planned enterprise controls are labeled so buyers can evaluate readiness without guesswork.

Identity and access

Access is governed by account, workspace, role, and deployment policy.

Current

Authentication

Pilot access is provisioned by A2AC. Production authentication options are reviewed during onboarding.

Available during onboarding

SSO and MFA

Enterprise SSO and MFA requirements are captured during security review and mapped to the chosen identity provider.

Preview

RBAC and admin controls

Administrative and workflow actions are scoped by role, workspace, and approved product surface.

Current

Tenant isolation

Tenant data is logically isolated by account and workspace. Dedicated isolation patterns are reviewed for enterprise deployments.

Current

Least privilege

Connected systems are accessed only through configured credentials, user permissions, and approved workflow policies.

Preview

Approval controls

Human approval can be required before governed actions are completed or sealed into final receipts.

Data protection

Customer content, credentials, and model traffic are handled as governed workflow data.

Current

Encryption in transit

Public traffic uses HTTPS. Internal service connections use managed Google Cloud transport controls.

Current

Encryption at rest

Managed Google Cloud services provide encryption at rest for stored operational data.

Current

Secrets

Operational secrets are stored in Google Cloud Secret Manager or equivalent managed secret storage.

Current

Model-provider data flow

The Google Cloud deployment uses Gemini Enterprise Agent Platform for hosted agent infrastructure and model access. Other API-based model endpoints are enabled only by deployment policy.

Policy

Training use

A2AC does not use customer workflow content to train A2AC-owned models. Provider-specific terms are reviewed during onboarding.

Available during onboarding

Retention and deletion

Retention, deletion, and export requirements are defined in the customer agreement and deployment policy.

Logging and governance

Workflows produce evidence, not just chat transcripts.

Current

Receipt records

Assignments, handoffs, approvals, and completed actions can be sealed into signed, hash-linked receipt records.

Preview

Audit visibility

Administrators can review task state, workflow status, receipts, and connected-system activity in supported surfaces.

Available during onboarding

Exportability

Receipt and audit export patterns are defined for enterprise pilots that need external review or archive workflows.

Operations

Operational expectations are defined before production use.

Current

Incident reporting

Report suspected issues to security@a2ac.ai with affected URL, account, timestamp, reproduction steps, and customer-content impact.

Available during onboarding

Response plan

Enterprise onboarding includes named contacts, severity definitions, and agreed response expectations.

Planned

Backups and recovery

Backup, restore, and recovery objectives are documented as part of production deployment planning.

Current

Dependency monitoring

Core services run on managed Google Cloud infrastructure with Cloud Logging and Cloud Monitoring support.

Available during onboarding

Vulnerability handling

Security reports are triaged with customer impact, exploitability, and remediation status tracked through the agreed support channel.

Planned

Availability targets

Formal SLAs are established by enterprise agreement before production dependency.

Legal and compliance

Procurement artifacts are handled during enterprise onboarding.

Available during onboarding

DPA

Data processing terms are reviewed with enterprise customers before production use of customer content.

Available during onboarding

Subprocessors

Google Cloud is the primary infrastructure provider. Additional subprocessors are disclosed through customer agreement as needed.

Planned

Certifications

SOC 2, ISO 27001, and similar third-party certifications are roadmap items, not current certifications.