Agentman › Security & Governance
Security & governance

In regulated work, automation without lineage is risk.

Agentman owns every layer of the agent stack — so every action an agent takes is logged, traceable, and reviewable before it touches a patient, a client, or revenue. Built for HIPAA from the architecture up, not bolted on after.

HIPAA + BAASOC 2 Type IIISO 27001GDPRCCPA
Why full-stack matters

Most AI tools are wrappers. We own every layer.

A wrapper on someone else's infrastructure can only see — and govern — its own thin slice. Because Agentman builds the skills layer, the agent runtime, the operations console, and the data plane, we can trace any output end to end and enforce your controls at every step. That's visibility a point solution structurally can't match.

It's also why our own regulated product, Medman, runs in live clinical environments — the governance had to be real before we'd put it near a patient record.

Operations & audit console Agentman
Agent runtime & orchestration Agentman
Skills & citations layer Agentman
Frontier models (native APIs) your choice
Governance built in

Three controls, on by default.

Data lineage

Trace every data point from source document to agent action to output. Every computed value carries the formula, inputs, and result behind it.

Audit logs

Immutable event trails for every agent decision and action — skill version, citation, timestamp, and operator captured on every step.

Access control

Role-based permissions, tenant isolation, and secrets management. Control who can view, edit, and publish — scoped by team, client, or matter.

"Where did this number come from?"

Every output traces back to its source.

The question every regulated team needs answered. Agentman pins every figure, extracted field, and narrative claim to the data and document it came from — a full chain you can follow, not a black box you have to trust.

Source documentpolicy · 270/271 · record
Skill & reasoningversioned, cited
Agent actionlogged, timestamped
Outputcopay · memo · claim
Compliance

Certified and maintained — for industries that require it.

HIPAA
Compliant processor; BAA available on request
Available now
SOC 2 Type II
Controls audited over time, not just a point in time
Available now
ISO 27001
Information security management standard
Ready
GDPR · CCPA
Data-subject rights and privacy controls
Available now

Every agent decision is captured with skill version, source citation, timestamp, and operator. Audit exports come in the formats internal and external auditors already accept.

Data protection

Your data stays yours.

Never used to train models

Your company data is never shared or used to train models — yours, always.

PHI under your boundaries

PHI stays within your tenant. Sensitive fields can be auto-redacted in views while preserving full data for authorized debugging.

Secure integrations

Controlled agent interactions with business systems follow your governance rules and stored-credential policies.

Tenant & workspace isolation

Agents, data, and credentials are isolated per workspace, so one engagement never bleeds into another.

Deployment

Deploy the platform your way.

Agentman runs in our managed cloud today — and deploys inside your infrastructure for organizations that require it.

Managed cloud

Secure, compliant, and zero infrastructure to manage. The fastest path to production for most teams.

Available now

On-premises

The full platform deployed inside your own infrastructure, for complete data sovereignty.

Coming soon

Air-gapped

Fully isolated deployments for classified and high-sensitivity environments.

On request
Built for regulated industries

The compliance bar, by sector.

Healthcare

  • HIPAA + BAA, PHI isolation
  • FHIR / HL7, 2,700+ payers
  • Auditable eligibility & claims

Financial services & PE

  • Per-field citation architecture
  • Deterministic math, no hallucinated figures
  • Audit trails for IC & LP reporting

Legal

  • Matter-scoped confidentiality
  • Source-cited reasoning
  • Reviewable before anything ships

Bring your security team.

We'll walk through the architecture, the audit model, and your deployment options — and share the documentation your reviewers need.