Security

Nothing leaves your network. Nothing changes without a human.

Built for environments where every action needs an owner and every decision needs a record.

0
inbound ports to open
0
bytes of phone-home
2
approvers to raise autonomy
100%
of actions on the ledger
01 · Deployment

Installs where your data already lives.

A Helm chart or a single host, inside your network. Models run on your GPU, or CPU for a pilot. Closed networks get an air-gap bundle with the weights included.

  • Helm chart or single-host bundle
  • Air-gap bundle, weights included
  • Outbound only, to tools you connect
ops@bastion · your network
$
02 · Data

Secrets are gone before anything is written.

Passwords, tokens, keys and card numbers are redacted on the way in. Prompts are stored redacted, with a hash of the original for proof.

  • No telemetry, no phone-home
  • No external model APIs
  • Card numbers caught by checksum, not pattern alone
ledger.write · redaction on 0 secrets stored
    03 · Control

    Humans hold the keys. Always.

    Every service starts in shadow. Letting 3AM act is granted per service and needs two people. Taking it back is one click, and the halt switch stops everything.

    • Shadow by default, per-service autonomy
    • Quorums, allowed hours, action budgets
    • Mandatory dry run, one global halt
    autonomy · per serviceoperating
    • core-banking-dbL1
    • payments-edgeshadow
    • messagingshadow
    • core-bankingshadow
    Raise payments-edge: shadow → L10/2
    ppriya.shahwaiting
    mmarcus.leewaiting
    One switch stops every action, everywhere.
    04 · Audit

    A record that proves it hasn't been touched.

    Every signal, check, approval and action is appended to a hash-chained ledger with signed segments. Change one byte and the verifier tells you exactly where.

    • Append-only, hash-chained, Ed25519-signed
    • Independent verifier for edits, gaps, reorders
    • Export to Splunk, syslog or S3
    ledger-verify --segment 3✓ verified · 523 events · signature ok
    #509approval.decidedhuman:dba-oncallhash 9f2c41e0prev 00000000
    #513action.executedorchestratorhash 4b7d0a93prev 9f2c41e0
    #520outcome.verifiedorchestratorhash c3e81f5dprev 4b7d0a93
    #521episode.closedorchestratorhash 71a6b2c8prev c3e81f5d
    05 · Safety by design

    Documents can suggest. Only evidence can act.

    Every source 3AM reads carries a trust tier. A runbook can point at a cause; only a live check against your systems can authorise a fix.

    TierSourceSuggestAct
    T1Code and schema✓yes
    T2Alert rules and live metrics✓yes
    T3Runbooks and wiki pages✓never
    T4Past postmortems✓never
    A structural rule in the pipeline, not a prompt instruction.
    06 · Supply chain
    Signed, distroless images
    SBOM with every release
    Offline, signed licence
    Source-free compiled build
    Read-only diagnostic credentials
    No shell access for the agent
    FAQ

    What your security team will ask.

    Have a vendor security questionnaire?

    Bring it to the demo. We'll walk your team through it line by line.

    Book a demo →
    Does any of our data leave the network?

    No. 3AM runs on your hardware and calls no external model or telemetry service. The only outbound traffic goes to tools you connect yourself, such as an approval request to your Slack.

    Do we need to open inbound firewall ports?

    No. Slack uses Socket Mode, Symphony its datafeed, and PagerDuty and other channels are polled. Every connection is opened from inside your network.

    Can 3AM change production without a person approving it?

    Not unless you allow it. Every service starts in shadow mode, where 3AM only proposes. At L1 each action needs one approval, raising a service needs two approvers, and a global halt stops everything at once.

    What stops it acting on the wrong root cause?

    Only a cause confirmed by a read-only check against your live systems can lead to a fix. Runbooks and past incidents can suggest causes but never authorise action, and every fix is dry-run first.

    Which AI models does it use?

    Open-weight models that run inside your install, on your GPU or on CPU for a pilot. There is no call to an external model API.

    How do our auditors verify what happened?

    Every event is written to an append-only, hash-chained ledger with signed segments. An independent verifier detects any edit, deletion, insertion or reordering, and the ledger exports to your SIEM.

    Can it run in an air-gapped environment?

    Yes. The air-gap bundle ships the images and model weights together, so nothing needs to be fetched at install time.

    Book a demo

    Your next incident is already scheduled.

    See 3AM resolve one live in 30 minutes, then start a shadow-mode pilot that changes nothing.