Authentication
Pilot access is provisioned by A2AC. Production authentication options are reviewed during onboarding.
A2AC is built for governed AI workflows on Google Cloud. Current controls, preview controls, and planned enterprise controls are labeled so buyers can evaluate readiness without guesswork.
Pilot access is provisioned by A2AC. Production authentication options are reviewed during onboarding.
Enterprise SSO and MFA requirements are captured during security review and mapped to the chosen identity provider.
Administrative and workflow actions are scoped by role, workspace, and approved product surface.
Tenant data is logically isolated by account and workspace. Dedicated isolation patterns are reviewed for enterprise deployments.
Connected systems are accessed only through configured credentials, user permissions, and approved workflow policies.
Human approval can be required before governed actions are completed or sealed into final receipts.
Public traffic uses HTTPS. Internal service connections use managed Google Cloud transport controls.
Managed Google Cloud services provide encryption at rest for stored operational data.
Operational secrets are stored in Google Cloud Secret Manager or equivalent managed secret storage.
The Google Cloud deployment uses Gemini Enterprise Agent Platform for hosted agent infrastructure and model access. Other API-based model endpoints are enabled only by deployment policy.
A2AC does not use customer workflow content to train A2AC-owned models. Provider-specific terms are reviewed during onboarding.
Retention, deletion, and export requirements are defined in the customer agreement and deployment policy.
Assignments, handoffs, approvals, and completed actions can be sealed into signed, hash-linked receipt records.
Administrators can review task state, workflow status, receipts, and connected-system activity in supported surfaces.
Receipt and audit export patterns are defined for enterprise pilots that need external review or archive workflows.
Report suspected issues to security@a2ac.ai with affected URL, account, timestamp, reproduction steps, and customer-content impact.
Enterprise onboarding includes named contacts, severity definitions, and agreed response expectations.
Backup, restore, and recovery objectives are documented as part of production deployment planning.
Core services run on managed Google Cloud infrastructure with Cloud Logging and Cloud Monitoring support.
Security reports are triaged with customer impact, exploitability, and remediation status tracked through the agreed support channel.
Formal SLAs are established by enterprise agreement before production dependency.
Data processing terms are reviewed with enterprise customers before production use of customer content.
Google Cloud is the primary infrastructure provider. Additional subprocessors are disclosed through customer agreement as needed.
SOC 2, ISO 27001, and similar third-party certifications are roadmap items, not current certifications.