You stay in control
Scrydon is built so that security is the default, not an add-on. Every external request crosses five gates before it reaches any service, the platform ships fail-closed, and your data, keys and AI stay inside your perimeter.
Fail-closed by default
If a check cannot be satisfied, access is denied. The secure outcome is the standard outcome.
Your keys, your perimeter
LOCAL, BYOK and HYOK key strategies keep encryption — and trust — on your side.
Provable & auditable
Immutable audit and framework evidence packs make control demonstrable, not just claimed.
Five gates, then fail-closed
- 1
Ingress hardening
Forged identity headers are stripped at the edge. Internal identity is never trusted from the outside; it is established inside the perimeter.
- 2
Authorisation
A single policy decision point evaluates every request as policy-as-code (Rego) across both the application and data planes.
- 3
mTLS service mesh
Services authenticate one another with mutual TLS. No shared bearer tokens, no implicit trust between workloads.
- 4
Secrets management
Credentials are encrypted at rest, scoped per grant and redacted in logs. A secret read without a valid grant fails outright.
- 5
DLP & audit logging
Outputs pass through the guardrails engine and every privileged operation is written to an immutable, queryable audit trail.
Fail-closed by default. Invalid mTLS identities are rejected, failed authorisation checks deny access, and workflows run under server-issued grants — never under user-supplied identities.
The guardrails engine
- PII detection: Model outputs are scanned for personally identifiable information before they leave the platform.
- Hallucination flags: Responses are checked against grounding so unsupported claims can be flagged or blocked.
- Regex & JSON gates: Pattern and schema validation enforce the exact shape of what may be returned.
- Exfiltration control: Guardrails sit on the egress path, preventing sensitive data from escaping in a response.
Zero-trust identity
Explore the underlying sovereign identity layer.
- Zero-trust by default: Workflows run under server-issued grants, never under user-supplied identities.
- SSO & SCIM: Connect your identity provider for single sign-on and automated user provisioning and de-provisioning.
- Three-tier model: Organisation roles, workspace membership and team grants compose into least-privilege access.
- Multi-tenant isolation: Tenants are isolated by design, so one organisation can never reach another's data.
Encryption on your terms
LOCAL
Platform-managed encryption. Credentials are encrypted at rest and redacted from every log line — the fastest path to a hardened default.
BYOK — bring your own key
You supply the encryption keys. Scrydon uses them to protect your data while you retain ownership and the ability to revoke.
HYOK — hold your own key
Keys never leave your custody. The platform operates against keys you hold, keeping ultimate control firmly on your side of the line.
External AI is opt-in. No request leaves for a third-party model unless you have explicitly allowed it, so sovereignty is a setting you control rather than a promise you have to trust.
An immutable record
Accountability is governed end-to-end by AI Governance, which ties policy, identity and audit into one control plane.
Controls that map to the frameworks you answer to
See the full compliance overview for the detail behind each mapping. Scrydon describes how its controls support these frameworks and produces evidence packs; it does not claim formal certification on your behalf.