Skip to content

Security & trust

Built so you don't have to take our word for it

AI Approvel sits in front of your AI agent's riskiest actions. That only works if the record of every decision is trustworthy, and provably so. Here is how we do it.

  • Tamper-evident audit trail

    Every state change is hash-chained: each event includes the hash of the one before it. Change any past record and the chain breaks. You get a complete, ordered history of who approved what and when.

  • Independently verifiable

    Each event is signed with Ed25519. The audit response ships the public key and the exact hashing formula, so you or an auditor can verify the whole chain offline without trusting AI Approvel.

  • Least-privilege keys

    API keys are scoped to a single project, shown once and stored only as a hash. Rotate from Settings; the old key stops working the moment you rotate.

  • Encrypted in transit and at rest

    All traffic is TLS. Data lives in Postgres with encryption at rest. Signing keys are held in an isolated vault, separate from application data.

  • Human in the loop by design

    Risky actions never execute on the agent's say-so alone. A person approves on WhatsApp or SMS, the first reply wins, and tap-to-confirm links keep link previewers and scanners from deciding.

  • Signed webhooks, safe targets

    Decision webhooks carry an HMAC-SHA256 signature over the timestamp and raw body. callback_url must be https on a public host; private, loopback and cloud-metadata addresses are rejected.

How verification works

Every audit response includes the public key, its key_id and the formula. Three checks, in order, prove the trail: the chain (each prev_hash equals the previous hash), the hash (recomputed with the formula) and the signature (Ed25519 over the hash).

Pin the key by key_id so a rotated key cannot silently re-sign history. The docs include a complete Node verifier.

Hash formula

sha256( prev_hash | event_type | canonical_json(payload) | created_at )

Signature
ed25519 over the event hash
Public key
spki-der-base64, returned with every trail
canonical_json
sorted keys, no whitespace, recursive
Webhook signature
HMAC-SHA256( secret, "timestamp.rawBody" )

Platform hardening

  • Strict Content-Security-Policy on every response
  • HSTS with preload
  • X-Frame-Options DENY, a Referrer-Policy and a Permissions-Policy
  • Sessions in secure, HTTP-only cookies, checked on the server before any dashboard page loads
  • Monthly quota enforcement is atomic, so parallel requests at the limit cannot slip past it
  • Error reports have authorization headers, cookies and key or token query values scrubbed; no session replay

Compliance roadmap

SOC 2 Type II is on our roadmap. The signed audit trail is designed to support governance requirements such as the human-oversight and logging obligations in Article 26 of the EU AI Act. Building on a regulated stack and need something specific? We will work with your security team.

Responsible disclosure

Found a vulnerability? Email security@ai-approvel.com. We respond quickly and credit responsible disclosure.