Appends only. Chained by hash. Verifiable.

Security & Trust

The Record is the Product, and It is Built to Be Believed

InterceptAI is an accountability control. Its oversight ledger only grows; every entry is chained to the one before it, and the database enforces immutability rather than good intentions in the application code.

oversight ledger · action → proof
liveSOC 2 track
Action
Decision
Record
Proof
IntegrityDB Enforced Append Only

No silent rewrites, even by the app itself.

VerificationThird Party Provable

Signed exports verify without trusting us.

IsolationTenant Scoped by Default

Redaction and least privilege throughout.

Authorized vs Actual · redaction-safe · independent by design

Audit Trail Integrity

Tamper Evidence Built into the Structure

Appends Only, Enforced by the Database

A trigger, plus revoked UPDATE/DELETE grants, means the application role can add to the ledger but can never rewrite it. This is what separates a real immutable audit log from a log file somebody promises not to edit.

Chained by Hash and Verifiable

Each entry commits to the previous entry. A verification pass re derives every hash and walks the links, pinpointing any alteration by sequence number.

Provable by an Outside Party

A signed export bundle verifies offline, and a periodic external anchor lets an auditor confirm the chain without needing our keys. Tampering after the fact stays detectable.

Attributable

Every consequential action, every approval with the name of the reviewer, and every undo with the name of the actor is recorded. Authorized against actual, across chains of agents.

Data Protection

Least Privilege, Tenant Isolation, and Redaction

Redaction by Construction

The record stores only hashes and summaries. No field holds raw arguments, and logs carry messages rather than arguments, headers, or bodies.

Tenant Isolation

Every read and write filters on the tenant, proven by a leakage test suite. A two role database keeps the runtime on least privilege.

Access and Secrets

Console roles come from your own identity provider over OIDC. Service credentials are issued per caller and rotate. Secrets load from the environment, a mounted file, or a vault. Never committed, never logged.

Compliance Groundwork

The Artifacts a Reviewer Will Ask You For

This is not the audit itself. It is the SOC 2 Type One groundwork that lets one begin. Every control points directly to its evidence inside the codebase.

01Policy

Security Policy

Access control, data handling, cryptography and key management, logging, availability, change management, and business continuity with disaster recovery.

02Model

Threat Model

Assets, trust boundaries, and threats mapped through the STRIDE framework, each paired with its mitigation.

03Evidence

Control to Evidence Map

SOC 2 trust services criteria mapped to controls, each naming a file, a migration, a test, or a document.

04Export

SIEM Export

Stream signed and redacted records into Splunk, object storage, or any HTTP collector, and manage console roles from your identity provider.

Each control names a file, migration, test, or doc, not a slide.

Resilience

Safe Under Load, and Safe When Dependency Fails

  • Fails Safe, Never Open

    If scoring or the ledger is unavailable, a high consequence action holds. Safety succeeds over availability, deliberately.

  • Scales Sideways

    The gateway holds no state, so run as many replicas as you need behind a load balancer. Any replica can resolve any held action, tested with no loss of correctness.

  • Backup and Recovery

    Back up and restore with the hash chain still verifying afterwards. Run managed Postgres with a standby and point in time recovery.