A platform with production access has to earn it
Infrapilot executes change against your most sensitive systems. That privilege is constrained by design: no stored credentials, no inbound network access, no customer data in model training, and an audit record that cannot be quietly edited.
Independently assessed, continuously
Reports, bridge letters and the current penetration test summary are available under NDA through your account team or the trust portal.
SOC 2 Type II
Security, Availability, Confidentiality · audited annually
ISO/IEC 27001:2022
Information security management system
ISO/IEC 27017
Cloud services security controls
ISO/IEC 27018
Protection of personally identifiable information
FedRAMP Moderate
Agency sponsorship secured · assessment under way
HIPAA
Business associate agreement available
GDPR
EU representative appointed · SCCs in place
TISAX
Automotive information security assessment
Four properties that make production access defensible
Each of these is a design constraint rather than a configuration option — they cannot be switched off, on any plan.
Zero standing privilege
No account the platform holds has standing access to your estate. Every credential is brokered from your vault at step start with a bounded lease, and revoked at step completion.
Policy before execution
Guardrails are evaluated ahead of every step, not audited afterwards. A change that violates policy never reaches a host, and the denial explains which rule stopped it.
Tamper-evident audit
Records are append-only and cryptographically chained. Altering or removing an entry breaks the chain and is detectable on verification, including by you.
Least-privilege by construction
Runners request only the specific capability a step needs. A patching workflow cannot read application data; a discovery scan cannot write configuration.
What crosses the boundary, and what never does
Self-hosted keeps everything inside your network. Dedicated cloud runs a single-tenant control plane in your chosen region, with runners still inside your perimeter.
Access plane
How people and systems reach the platform
Control plane
Stateless services, horizontally scaled, no customer credentials at rest
Execution plane
Runners you deploy; outbound-only connections, no inbound firewall rules
Managed estate
Reached over native protocols — no agent required for discovery
What we hold, for how long, and where
Infrapilot is an operations platform, not a data platform. The information it retains is metadata about your estate and the actions taken against it — not the contents of your databases, files or messages.
- Configuration and topology metadata, retained for the life of the agreement
- Execution records and audit entries, retained per your plan’s policy
- Diagnostic evidence collected during incidents, retained 90 days by default
- No table contents, file payloads or message bodies are read or stored
- Regional data residency in EU, US, UK, Australia, Canada, Japan and Singapore
$ infrapilot audit verify --from 2026-07-01 --to 2026-08-01
Verifying 1,284,402 entries ......................... ok
Recomputing chain digests ........................... ok
Comparing against notarised checkpoints (31) ........ ok
entries 1,284,402
first 2026-07-01T00:00:04Z
last 2026-07-31T23:59:51Z
root digest sha256:9f2c41e0…b73a
checkpoints 31 / 31 matched
discrepancies 0
Chain verified. No entry has been altered or removed.Fits the identity model you already run
SSO and SCIM
SAML 2.0 and OIDC with Entra ID, Okta, Ping and Google Workspace. SCIM 2.0 provisioning keeps membership and deprovisioning automatic.
Fine-grained RBAC
Roles scoped by environment, asset class, region and business unit. Permission to run a workflow is separate from permission to author or approve it.
Session recording
Interactive sessions initiated through the platform are recorded and attached to the change record, including keystroke-level capture where policy requires it.
The questions your security team will ask first
If your review requires a completed CAIQ, SIG or bespoke questionnaire, your account team will return it within five working days.
No. Credentials are requested from your broker — CyberArk, HashiCorp Vault, Azure Key Vault or an equivalent — at the moment a step begins, held in runner memory for the duration of that step, and revoked on completion. Nothing is written to disk and nothing is persisted in the control plane.
Runners establish outbound TLS 1.3 connections to the control plane. No inbound firewall rules, no VPN into your estate and no public exposure of managed systems are required. In self-hosted deployments the control plane never leaves your network at all.
Never. Risk models are trained per tenant on that tenant’s own change history and are not shared across customers. Copilot uses retrieval over your data at inference time; prompts and responses are not retained for training and are excluded from any foundation-model provider’s training pipeline by contract.
Runners hold no long-lived credentials and no customer data at rest, which limits the value of a compromise. Each runner has an individually revocable identity; revoking it terminates in-flight leases immediately. Runner binaries are signed and verified on start, and job manifests are signed by the control plane.
Every action, parameter, approval, output and policy decision is written to an append-only ledger with cryptographic chaining, so any modification is detectable. The ledger is queryable over API and exportable to your SIEM. Retention is twelve months on Foundation, seven years on Enterprise, and configurable on Sovereign.
We run continuous dependency and container scanning, annual third-party penetration testing with summary reports available under NDA, and a coordinated disclosure programme. Critical findings are remediated within seven days and communicated to affected customers within the contractual notification window.
Start the review before the commercial conversation
We would rather your security team said no in week one than week twelve. Ask for the security pack — SOC 2 report, penetration test summary, architecture documentation and completed questionnaires.