SECURITY & GOVERNANCE

Trust isn't a feature.
It's the foundation.

mploi was designed for organizations where data sovereignty and auditability are not negotiable. Every architectural decision starts with this constraint.

ENFORCEMENT LOG

Guardrails in action — live

mploi — policy enforcement log
FIRST PRINCIPLES

Four non-negotiable principles

The principles your security and compliance teams will recognize on day one.

Data Sovereignty

mploi runs entirely on your infrastructure — on-premises, in your private cloud, or in air-gapped environments. There is no SaaS backplane, no analytics phone-home, no required external dependency. Your data, your conversations, your audit logs, and your model traffic stay inside the boundary you draw.

Deterministic Execution

Security is enforced by the platform, not by prompt instructions. When an agent isn't permitted to invoke a tool, the platform blocks the invocation — regardless of what the model decides. Permissions, tool access, and data scoping are concrete, testable, and auditable.

Complete Transparency

Every conversation, every tool invocation, every authentication event, and every administrative change is recorded in a structured activity log. Your security team can answer "what did this agent do, on whose behalf, with what data?" — exhaustively, for any moment in the system's history.

Model Portability

mploi is not built around any single AI provider. Switch models per-agent at any time, run open-source models on your own GPUs, or restrict regulated workloads to private inference. You retain leverage; you avoid vendor lock-in.

THE AUDIT

The controls your auditors will ask about

Every box on the security questionnaire — answered in the platform, on day one.

01 // IDENTITY & ACCESS

Single sign-on & group-based access control

Integrate with your existing identity provider — Azure Entra ID, Okta, Google Workspace, Keycloak, or any standards-compliant OIDC source. Users sign in with the credentials they already have, with the same MFA and conditional-access policies their other tools enforce.

Every primary object in the platform — agents, tools, knowledge sources, MCP servers, dashboards — has its own group-based access control. Your finance agents stay invisible to marketing. Your production database tool stays invisible to interns. Granularity is per object.

mploi · identity & access
Group-based access control and guided MFA security setup in mploi
mploi · secure credentials
Secure credential collection — values pass straight to the tool; the AI model never sees them
02 // DATA LOSS PREVENTION

Sensitive data never reaches the model

Built-in pattern recognition automatically detects and masks dozens of categories of sensitive data — SSNs, credit cards, API keys, email addresses, phone numbers, IP addresses, internal identifiers — before any model sees them. Add custom regex patterns for organization-specific identifiers in minutes.

Masking is transparent: the model sees opaque tokens; original values are restored only on the way back to the authorized user. And when an agent needs credentials to act, they're collected in a secure side channel that passes them straight to the tool — never through the model. Compliance gets a clear answer to "did the AI ever see this PII?" — with the audit log to prove it.

03 // EXECUTION GUARDRAILS

Hard boundaries on what agents can do

Tool permissions are enforced at the platform layer — independent of the model's reasoning. If an agent isn't authorized to query production, the query never reaches production. No prompt injection can change that. No clever rephrasing gets around it.

Require human confirmation for any destructive operation — and when a human says no, the denial (with their reason) becomes part of the record, as in the run shown here. Plan mode forces the agent to draft a proposal before executing. Every invocation is recorded with exact arguments, result, timestamp, and the identity that authorized it.

mploi · tool denial
A tool call denied by the user with a comment — the agent acknowledges and the denial is audited
mploi · session history
Full session history with tool calls, generated documents, and token usage retained for review
04 // AUDIT & OBSERVABILITY

Answer "what happened?" definitively, for any window

Activity logs capture every action: user authentications, configuration changes, agent runs, individual tool invocations, document uploads, permission edits. Each entry is structured, queryable, and exportable.

The token usage of every model call is captured. The full conversational context is retained per-session. Compliance reviewers can reconstruct the complete history of any interaction — what was asked, what the agent did, what data it touched, and what was returned.

THE CHECKLIST

Designed to pass your compliance review

A quick checklist of the controls your security team will look for.

Data residencyAll data and traffic stay inside your environment.
Air-gap supportedCan operate without external network access.
No telemetry phone-homeNothing reports back to a vendor.
BYO modelUse private inference for sensitive workloads.
SSO via OIDCIntegrate with your existing IdP.
Group-based permissionsObject-level access control across the platform.
Data-loss preventionBuilt-in and customizable masking.
Tool-level policyEnforced at the platform, not by the prompt.
Human-in-the-loopRequire confirmation for destructive actions.
Plan modePropose-before-execute for any agent.
Activity auditStructured, queryable log of every action.
Session continuityFull conversational context retained for review.
DEPLOYMENT MODELS

Deployment that fits your risk profile

mploi is the same product across deployment models. Pick what your security posture requires.

On-premisesBare metal or VMs in your own data center.
Private cloudAWS, Azure, GCP, OCI — anywhere you control.
Air-gappedFully offline, no external dependencies.
HybridSensitive workloads private, others to cloud providers.
mploi · providers
Commercial providers and private vLLM inference connected side by side
DEEP DIVE

Want the full
security briefing?

Our team is happy to walk your security and compliance leadership through the platform's controls in detail.

Request a Security Briefing