Security

Controls for the systems your AI can access and the actions it can take.

Polyosync is designed around permissions, tenant boundaries, protected credentials, auditability and controlled AI actions. Security controls are part of the platform architecture.

Security controls

Access is controlled at the workspace, resource and action level.

01

Permissions

AI Employees operate within configured roles, capabilities, integrations and permissions. Protected operations are subject to authorization checks.

02

Encryption

Sensitive OAuth and API credentials are encrypted or otherwise protected server-side. HTTPS/TLS protects data in transit. We do not make blanket encryption-at-rest claims beyond verified provider and application controls.

03

Tenant isolation

Business-level isolation is enforced through tenant-scoped authorization and database access controls. A business workspace is the application data boundary for protected resources.

04

Audit

Security and audit telemetry records relevant authentication, authorization and operational events so activity can be investigated.

05

Access control

Resource-level access checks and workspace membership controls restrict who can access protected business resources and actions.

06

Approvals

Configured approval policies can require human approval before defined AI actions are executed.

Operational security

Security telemetry and operational resilience.

Polyosync tracks relevant authentication, API, workflow and security signals for investigation, incident response and service reliability. Privileged Platform Admin access has additional controls, including authenticator-app TOTP MFA on the relevant routes.

No unsupported certification claims

This page describes implemented controls and documented practices. Polyosync does not claim SOC 2, ISO 27001, penetration-test certification or another independent certification unless that certification is actually held and documented.

Related controls

Privacy and responsible AI are part of the same operating model.

Copy system

Understand security and control before you buy it.

Every Polyosync page answers the same operational questions. No vague AI claims: what it is, what it does, how it operates, what it automates, and where people stay in control.

01What is it?

The controls around AI execution: permissions, access boundaries, credential protection, tenant isolation, audit and human intervention.

02What can it do?
  • •Define who and what can act
  • •Protect connected credentials and access
  • •Review operational security events
  • •Keep human approval and intervention paths available
03How does it work?

Role + business knowledge + capabilities + authorised tools + integrations + defined workflows. The configuration determines what the AI can access and do.

04What does it replace / automate?
  • •Security-sensitive checks and operational controls around AI execution
  • •Audit and review workflows
  • •Defined access and action boundaries
05What control do I have?
  • •Permissions and access control
  • •Approval policies and action boundaries
  • •Audit and operational visibility
  • •Human intervention
06Who is it for?

Teams evaluating how AI execution is constrained and governed in a business environment.

07What does it connect to?
  • •Identity and access controls
  • •Connected integrations
  • •Audit and security telemetry
  • •Business workflows
08What happens when AI needs a human?

Controls can stop, approve or route work to people instead of allowing AI to continue outside its defined authority.

09How does it scale?

Apply the same control model from individual employees to broader AI workforce deployments and enterprise environments.

Availability

Security capabilities described here reflect the current product architecture; they should not be read as unsupported certification claims.

See it in the product →