Security
Security and Responsible Disclosure
MAX-AI Guard is a pre-action control layer for AI agents. This page describes current handling practices and boundaries without claiming compliance certifications.
Responsible Disclosure
Report suspected vulnerabilities to security@max-ai-guard.com. Include reproduction steps, affected routes or APIs, expected impact, and whether any data was accessed.
Security Contact
security@max-ai-guard.com
Data Processed
Action proposals, actor or agent identifiers, role, tool name, target, recipients, document IDs, data classes, minimal content preview, decision metadata, audit events, and receipt artifacts.
Data Not Allowed In Pilots
Medical records, child or minor records, payment card data, SSNs, regulated personal data, legal advice requests, and production secrets unless separately approved in writing.
Provider Usage
The demo can run with a mock provider. Deployments can configure model providers behind a provider boundary; only the minimum action context needed for evaluation should be sent.
Retention
Audit and receipt retention are policy-controlled in the application. Custom retention, legal hold, and deletion workflows are enterprise design-partner items.
Access Controls
Owner, admin, reviewer, member, and viewer roles shape policy management, approvals, exports, and external effects. API access uses hashed keys at rest.
Incident Process
Triage report, reproduce safely, assess impact, preserve relevant logs/receipts, mitigate, notify affected pilot operators when appropriate, and document remediation.
Receipt integrity is hash-only today. Signed external verification, managed SIEM export, private deployment review, DPA, SLA, and formal audit evidence packages are roadmap/design-partner items.