Security

Security and Responsible Disclosure

MAX-AI Guard is a pre-action control layer for AI agents. This page describes current handling practices and boundaries without claiming compliance certifications.

Trust overview

Responsible Disclosure

Report suspected vulnerabilities to security@max-ai-guard.com. Include reproduction steps, affected routes or APIs, expected impact, and whether any data was accessed.

Security Contact

security@max-ai-guard.com

Data Processed

Action proposals, actor or agent identifiers, role, tool name, target, recipients, document IDs, data classes, minimal content preview, decision metadata, audit events, and receipt artifacts.

Data Not Allowed In Pilots

Medical records, child or minor records, payment card data, SSNs, regulated personal data, legal advice requests, and production secrets unless separately approved in writing.

Provider Usage

The demo can run with a mock provider. Deployments can configure model providers behind a provider boundary; only the minimum action context needed for evaluation should be sent.

Retention

Audit and receipt retention are policy-controlled in the application. Custom retention, legal hold, and deletion workflows are enterprise design-partner items.

Access Controls

Owner, admin, reviewer, member, and viewer roles shape policy management, approvals, exports, and external effects. API access uses hashed keys at rest.

Incident Process

Triage report, reproduce safely, assess impact, preserve relevant logs/receipts, mitigate, notify affected pilot operators when appropriate, and document remediation.

Receipt integrity is hash-only today. Signed external verification, managed SIEM export, private deployment review, DPA, SLA, and formal audit evidence packages are roadmap/design-partner items.