Trust posture

Trust Overview

MAX-AI Guard is designed as a pre-action authorization layer for AI agents. This page distinguishes implemented controls from enterprise roadmap items and avoids certification claims.

Security overview

Pre-action evaluation, deterministic deny rules, RBAC checks, audit events, and receipt generation are implemented in the v1 codebase.

Data processed

Action metadata, actor or agent identifiers, tool names, data classes, recipients, document identifiers, and minimal content previews can be evaluated.

Data not allowed in pilots

Medical records, child or minor records, payment card data, SSNs, legal advice, and regulated personal data are blocked unless separately approved in writing.

Provider usage

Mock AI is the default demo provider. OpenAI and Anthropic are isolated behind a provider interface and can be configured per deployment.

Access controls

Owner, admin, reviewer, member, and viewer roles shape approvals, exports, external effects, policy changes, and control-plane access.

Audit and receipts

Decisions, approvals, denials, policy changes, and receipt generation are recorded for review, CSV export, JSON export, and evidence collection.

Retention

Receipt retention and audit retention are configurable in policy settings. Enterprise custom retention is roadmap/design-partner work.

Deployment model

The app supports local demo mode and PostgreSQL-compatible production persistence when configured by the deployment operator.

Responsible disclosure

Security reports should be sent to security@max-ai-guard.com. Include affected endpoint, reproduction steps, impact, and contact details.

Enterprise roadmap

SAML/OIDC, SCIM, managed SIEM exports, private deployment review, SLA, signed receipt verification, and formal audit evidence packages are roadmap/design-partner items.

Data flow

User/agent
Action proposal
Policy evaluation
Decision
Approval if required
Receipt/audit event
Optional export

The firewall should receive only the action metadata and minimum content preview needed for policy evaluation. Sensitive pilot data must not be connected without a written approval path.

Security contact

security@max-ai-guard.com

Send responsible disclosure reports with affected endpoint, reproduction steps, observed impact, and preferred contact details.

Procurement checklist

ArtifactStatus
DPADraft
Subprocessor listDraft
SSORoadmap
SCIMRoadmap
SIEMRoadmap
External audit packageRoadmap
Pen testRoadmap
SLARoadmap

Enterprise roadmap

SAML/OIDC, SCIM, managed SIEM exports, mobile approvals, private deployment reviews, signed receipt verification, and formal compliance mappings are tracked as enterprise readiness work.

Do not connect unapproved sensitive pilot data. Medical records, legal advice, child or minor records, Social Security numbers, payment card data, and regulated personal data require separate written approval and data-handling review.