Security
Security you can read off the architecture
The differentiator of this platform is not a security feature, it is the security architecture. The AI proposes; it never holds a credential, and it never has a path to execution that a human has not opened. This page is the long-form version of that claim.
The same credential-less boundary the homepage introduces, in full.
Zero standing credentials
The control plane orchestrates incidents and reasons over evidence, and it holds zero standing credentials to your infrastructure. No keys, no tokens, no shells. Secrets live only inside a gateway that runs on your side of the boundary, and that gateway dials out: there is no inbound path for anyone to abuse.
Two enforcement layers stay independent. The control plane evaluates policy; the gateway re-validates every job against its own local allowlist and never treats a control-plane signature as authority to run something off-list. A compromised control plane still cannot run an action your allowlist does not contain.
Approval is architecture, not a setting
There is no execution path around the policy gate. Model output is data, quarantined until it passes that gate, and in v1 every change is approved by one of your engineers before anything runs. Approval is not a toggle a rushed operator can switch off; it is where the only path to execution goes.
When production automation arrives later, it inherits the same gate, the same allowlist, and the same audit trail. It does not route around them.
Prompt-injection containment
We assume prompt injection. Logs, tickets and alerts are attacker-influenceable text, so the model's output is treated as untrusted from the moment it is produced. We do not claim to prevent injection; we contain its consequences.
A poisoned suggestion is still just a proposal: quarantined, evaluated against your policy, shown to a human, and finally bounded by a local allowlist only your side controls. The worst an injected instruction can ask for is something your allowlist already permits and your engineer already approved.
Security incidents are never auto-remediated
Operational incidents can, with approval, lead to an allowlisted fix. Security findings never do. Auto-mutation on attacker-influenceable signals destroys forensic evidence and can be triggered by the attacker on purpose, so a security finding is routed to an evidence-preserving containment lane where a human drives every step.
This is a path we refuse to build, not a switch we ship turned off.
Built for segmented and regulated environments
Strongly segmented networks stay segmented. Each segment gets its own gateway, each outbound-only, each enforcing its own local allowlist, so nothing has to open a lateral path to make the platform work.
Sensitive data is redacted on the gateway side before anything crosses the boundary, inference can run against your own on-premises vLLM deployment, and the control plane itself can be provided in your own datacenter. The result is designed for DSGVO-sensible and regulated environments, without a certification claim we have not earned.
Run it against your real incidents, as a design partner
Vesmona is in private beta. We're looking for a small group of teams who'll run the platform on real incidents and tell us where it falls short. You get early access, a direct line to the engineering team, and a real say in the roadmap. We get the operational reality (and, where it's earned, the reference) that makes a platform product-ready.
Become a design partner