TRUST CENTER
Governed by design. Documented by default.
Every Kascade agent runs inside guardrails your team approves, with a named human on every consequential action and a log entry for everything. This page is the public record of how that works.
The controls, in plain language.
SOC 2 TYPE II
Kascade maintains SOC 2 Type II coverage; the report is available under NDA.
ROLE-BASED ACCESS
Access is scoped to named individuals and roles. Agents and people alike see only what their role grants.
AUTOMATIC REDACTION
Sensitive data is redacted automatically outside the scope that needs it.
AUDIT LOGGING
Every agent action is logged: what it did, why, and under whose guardrail.
HUMAN APPROVAL
Consequential actions wait for human approval inside guardrails you set; reserved judgment calls reach your team with a recommendation.
PAUSE AT ANY TIME
Agents run on access you grant and can be paused at any time. Any process can be taken back manually.
CONTROLLED DEPLOYMENT
Changes are built and tested in separate environments before they reach production. Nothing ships straight to prod.
Where the boundaries sit.
The diagram below is the delivery model's governance layer: where access is granted, where redaction happens, where approval gates sit, and where the log records it all.
Your systems
& data
Access you grant · scoped by role
Sensitive data redacted at the boundary
The Kascade layer
AI agents · Run the work
Consequential ↓ ↑ Approved
Our experts · Own the outcome
The record
Every action
every approval
every exception
all logged
Reserved judgment calls → you, with a recommendation
Your cloud or ours. Your review, in parallel.
Kascade deploys in your cloud or ours. The governance model is identical either way. And your security review doesn't gate the timeline: it runs in parallel from day one, so the first agent is in production in four to six weeks while your team completes its diligence with everything it needs.
The full pack, under NDA.
Some material doesn't belong on a public page. Under NDA, your security team gets the complete pack:
SOC 2 Type II report
Data-handling and retention practices
Subprocessor and platform posture
Access-control and redaction configuration detail
Incident-response and escalation procedures
Ask for it on the first call.
Bring your security team to the first call.
Thirty minutes covers the delivery model, the governance boundaries, and what the pack contains, for your operators and your reviewers in the same room.