Auron
Platform

Security

Tenant isolation, deployment options, identity integration and the controls behind them.

Auron holds conversations, which means it holds some of the most sensitive material an organization produces. The security model is built around that.

Tenant isolation

Every object belongs to one organization, and the boundary is enforced rather than assumed. Inside an organization, access narrows further to the records a person or team has been granted, and that access carries through to everything attached to those records. See Organizations and access.

Customer-specific deployment

For customers with elevated requirements, Auron can be deployed into an environment dedicated to them, so data, credentials and operational controls are isolated from other tenants rather than logically separated within a shared one.

This is the route for regulated industries, for data residency requirements, and for anyone whose own obligations extend to their suppliers.

Operational posture

Auron operates to a SOC 2 aligned posture: access to production is controlled and reviewed, changes are tracked, and activity in the platform is auditable. Outputs carry provenance, so what an agent produced and what it acted on can be reconstructed after the fact rather than taken on trust.

Identity

Single sign-on integrates Auron with your existing identity provider, so accounts are created, authenticated and removed through the process you already run. Where single sign-on is in use, passwords are managed by the provider rather than by Auron, and offboarding someone there removes their access here.

Without it, accounts sign in with an email and password, and email addresses are verified before use.

Credentials for other systems

Connections to your other systems keep their credentials centrally, in Secrets, rather than embedded in an agent's configuration. Keys are write-only once saved: they can be replaced but not read back. Toolkits use them without exposing them to the agent's instructions.

Your own model access

Organizations that need model usage on their own account, for contractual, billing or residency reasons, can bring their own keys and point agents at those configurations instead of the platform models.

Privacy inside a conversation

Not every conversation should widen what the organization knows. A private conversation still produces its summaries and drafts for immediate use while being blocked from updating shared memory, which lets a sensitive discussion benefit from an agent without leaking into shared context.

On this page