These are the questions security, compliance, and engineering teams ask before they buy. If yours isn't here, ask us directly.
No. The SDK logs asynchronously and fails open. If our API is unreachable, your agents keep running and logs buffer locally until the connection is restored. We are never in your critical path in the default deployment.
UK region by default, AWS eu-west-2 (London), a single region to start. Data is isolated per tenant, encrypted at rest with AES-256, and encrypted in transit with TLS 1.3. Multi-region deployment is on our roadmap for customers who need it.
By default we log metadata only: which agent, which tool, which data source, when. You choose whether payloads are logged, redacted, or hashed. PII redaction happens at the SDK level, before data ever leaves your network, so sensitive content never has to reach us in the first place.
Observability tools are built for debugging quality: did the agent respond well, where did the chain break. BastionShield is built for governance: identity, permissions, tamper-evident audit logs, and regulator-ready exports. They solve different problems for different buyers: engineering versus compliance and security.
We are SOC 2 aligned and currently in our Type I audit window. We'll share our report and timeline directly with customers running a vendor security review.
Not yet, but it's on the roadmap. We run as managed SaaS today. Next is a self-hosted gateway for the data plane, so sensitive traffic never leaves your environment. Full on-prem deployment for regulated buyers follows after that.
No, not silently. Support and operations run on a separate identity plane, they are not tenant users, and there is no all-tenant super account. Any cross-tenant access is break-glass: it needs a reason, your consent, a second approver for production data, and it auto-expires. Every such action is hash-chained and written into your own audit log, so you see exactly what we did and when.
No. Exceeding your quota is a billing event, not a security event. The gate keeps serving, overage is billed at your plan rate, and you get alerts at 80, 100, and 120 percent. Hard-stopping enforcement because an invoice grew would be exactly the kind of failure we exist to prevent, so we do not do it.
Every event is linked into a keyed hash chain, so any edit, deletion, or reorder breaks the chain and is detectable. You can verify the whole chain on demand, and we anchor it daily. This is the difference between a log you have to trust and evidence you can prove.
The decision path is deterministic, no model call, and returns in low single-digit to mid double-digit milliseconds at the 99th percentile under load. The SDK also caches a signed copy of your policies locally, so if our control plane is ever unreachable your agents keep making correct decisions at the edge. You are never blocked waiting on us.
Yes. We run an internal penetration test covering authentication bypass, cross-tenant isolation, privilege escalation, injection, and SSRF, and we hold a written report we share with buyers under NDA. Tenant isolation is verified with two independent layers. An independent third-party pen test is scheduled before general availability, and we welcome your own security team testing us.
A SIEM stores what happened. Bulwark records why an action was allowed: the initiating identity, the policy and version applied, what the AI recommended, who had authority to approve, and the outcome, as a single verifiable decision receipt. Telemetry tells you what happened; governance evidence tells you why it was permitted. You can still stream everything to your SIEM as well.
We are deliberately honest about this. The high-risk obligations were delayed to 2027 and 2028, so we do not sell false urgency around them. What is live now is the Article 50 transparency duty and the very real problem that most organisations cannot say what AI they are running. We help with the parts that apply today, and our framework mappings are supporting evidence, not a certification claim.
No. Your data is not used to train any model, ours or anyone else's. The enforcement engine is deterministic rules, not a model that learns from you. Any advisory intelligence runs on your tenant only and never leaves it for training.
Your governance data is yours. You can export your full audit trail and configuration at any time in open formats, and on cancellation you can take everything with you before deletion. A source-code escrow arrangement for enterprise customers is on the roadmap so your controls survive us regardless.
Yes. The Developer tier is free, no card required, and includes the full deterministic policy engine, the registry, the audit trail, and live monitoring. You only pay when you outgrow it. Paid plans are metered on decisions, so you are never charged per seat for a governance layer everyone should be using.
Talk to us directly. No sales deck required, we'll walk through your specific architecture and compliance requirements.