Trust & Security
Security and transparency are built into how Oconee Runtime operates.
Oconee Runtime is designed to help organizations govern AI activity while maintaining clear controls around access, data handling, auditability, and operational security.
Trust center
Where to start
Each section describes current practice. Where a control is provided by our infrastructure providers rather than by Oconee directly, it says so.
Security
Authentication, access control, tenant separation, encryption, audit logging and secure development practices.
Privacy
What information Oconee Runtime collects, why, and how marketing analytics stays separate from product and customer data.
Data handling
What the platform captures, what it deliberately avoids retaining, and how storage, retention and deletion work.
Subprocessors
The third-party providers used to operate the service, what each one receives, and where they operate.
Enterprise security review
Security documentation, architecture and data-flow overviews, and questionnaire responses for evaluating teams.
Architecture
How a governance decision is made
A conceptual view of what Oconee Runtime evaluates and what it keeps afterwards.
- 01
AI / agent activity
A coding agent, IDE assistant or browser AI tool attempts an action.
- 02
Oconee Runtime
The attempt is observed at the point of action.
- 03
Context + policy evaluation
Actor, agent, action, resource and context are evaluated against the organization's policy.
- 04
Decision
Allow, warn, block or redact.
- 05
Audit evidence
The decision and the context that produced it are recorded.
Boundary
Customer environment
Developer machines, browsers, IDEs and repositories. Extensions and the IDE integration observe AI activity here and send governance metadata to Oconee Runtime.
Boundary
Oconee Runtime
Policy evaluation, decision records, audit evidence and the administrative dashboard. Data is scoped to the organization it belongs to, and the database and cache are not reachable from the public internet.
Boundary
External integrations
Systems a customer chooses to connect — an identity provider for single sign-on, a notification destination, or their own SIEM receiving exported events. These are configured by the customer and are not required to run the platform.
Compliance
Oconee Runtime is not currently SOC 2 certified. Formal SOC 2 readiness is part of our compliance roadmap as the platform and customer base grow. Enterprise customers can contact us for current security documentation and review materials.
Oconee may map security and governance controls to relevant frameworks over time based on customer requirements. Framework mapping does not itself constitute certification.
Evaluating Oconee Runtime?
Enterprise prospects and existing customers can request current security information for a vendor review. Depending on the stage of your evaluation, that can include:
- Security architecture overview
- Data-flow overview
- Data-handling information
- Subprocessor information
- Retention configuration information
- Deployment and hosting information
- Access-control information
- Security questionnaire responses