Security and trust

What we do, and what we do not have yet.

Anthouse is an early company. This page is written so your security team can check it rather than take our word for it, which means the second half is as important as the first. If something is missing here, ask us at security@anthouse.io and we will answer plainly.

Where your data lives

Apps you deploy, and the databases behind them, run in the European Union. The workspace record, sharing rules and audit log are in an EU region. Sign-in is the exception and is described below.

ProcessorWhat it doesWhere
CloudflareRuns your deployed apps and their databasesEU (apps created with EU jurisdiction)
SupabaseWorkspace, app registry, sharing rules and audit logEU region
ClerkSign-in and user accountsUnited States
VercelThe Anthouse dashboard itselfGlobal edge, EU primary
StripePaymentsUnited States and EU
Amazon Web Services (KMS)Wrapping the key that encrypts your secretsEU (eu-central-1)

We will give you 30 days notice before adding a processor that handles customer data, and this list is the canonical one.

What is in place today

Secrets are encrypted, properly

Every secret is encrypted with AES-256-GCM under a per-app data key, which is itself wrapped by a key encryption key that never touches the database. In production that key lives in AWS KMS.

Every deploy is scanned before it goes live

Anthouse reads the source of each version and checks for credentials left in the code, code built from strings at runtime, database queries assembled by concatenation, writes with no identity check, and calls to addresses not on your allow list. Findings name the file and line, and secrets are masked before they are shown back to you.

Authorization is checked per request, not at the edge

Middleware and edge gateways are not security boundaries. Every mutating endpoint independently re-verifies the caller against the workspace roster.

Agents cannot exceed the person they act for

An AI agent operating an app inherits that person's role and can never do more. What agents may do per app is set by the app owner or a workspace admin, and agent actions are written to a separate audit trail from human actions.

Every app has a named owner

Ownership is derived from the workspace roster, so when someone leaves, their apps show as unowned rather than quietly continuing to run.

Nothing is deleted when you stop paying

Apps drop to free limits and become read-only. You can export the source at any time.

What we do not have yet

Listed so you are not surprised by it in a questionnaire.

SOC 2 Type II

Not started. We will begin the readiness period when a customer contract requires it, and we will say so here when we do.

ISO 27001

Not held.

EU-resident authentication

Your app data and your workspace records are in the EU. Sign-in is currently handled by Clerk in the United States under the EU-US Data Privacy Framework and Standard Contractual Clauses. Moving authentication to an EU-hosted provider is on our roadmap and we will not claim it until it is done.

Penetration test

Not yet commissioned. Planned before the first regulated customer goes live.

Runtime enforcement of agent permissions

Agent permissions are set, recorded and audited today. Refusing a disallowed agent action at the request path itself is in progress. Until it ships, treat the setting as a policy record rather than a hard control.

Status page

Coming. Until then, incidents are communicated by email to workspace admins.

Control and evidence, not just visibility

Finding apps is the start, not the product. Actions routed through Anthouse are checked against each app's policy at the moment they happen.

A runtime gateway

Reads pass under a read-only policy. Risky writes wait for a named human to approve — approvals expire in 30 minutes and work exactly once. A revoked app stops answering everywhere, instantly, and can be restored just as fast.

Tamper-evident logs

Every decision — allowed or refused — is written to a hash-chained log. Editing or deleting any past entry breaks the chain detectably. Your auditor can verify it without trusting us.

Honest scope

Enforcement covers actions that pass through Anthouse: the MCP endpoint agents use and the data paths apps adopt. Apps we only discovered but that run elsewhere get ownership, posture scoring and evidence — not runtime control — until they migrate onto the pipe. We say this here so you never find it out in an incident.

Your exit path

You should be able to leave. A governance vendor that holds your apps hostage cannot be trusted to govern them.

Apps export as plain files

Anything deployed through Anthouse downloads as a zip of ordinary web files — no proprietary framework, no runtime lock. They run on any static host the moment they are unzipped. This is promised in our terms, and the export endpoint exists today.

Discovery credentials are yours

Every connector is read-only and revocable on your side — Google admin, GitHub settings, your Entra tenant — in one click, without asking us.

The record travels with you

Each app carries a handover pack: owner, version history, who deployed what and when. Registers and event logs export as files. What cannot move is the live, continuously verified evidence chain — history can be copied, not re-created, which is the honest reason customers stay.

Reporting something

If you believe you have found a vulnerability, email security@anthouse.io. We will acknowledge within one business day and keep you updated until it is closed. We will not pursue legal action against good-faith research that does not access other customers' data or degrade the service.

For a DPA, a subprocessor change notification, or a completed security questionnaire, the same address reaches us.