TRUST CENTER

Governed by design. Documented by default.

Every Kascade agent runs inside guardrails your team approves, with a named human on every consequential action and a log entry for everything. This page is the public record of how that works.

The controls, in plain language.

SOC 2 TYPE II

Kascade maintains SOC 2 Type II coverage; the report is available under NDA.

ROLE-BASED ACCESS

Access is scoped to named individuals and roles. Agents and people alike see only what their role grants.

AUTOMATIC REDACTION

Sensitive data is redacted automatically outside the scope that needs it.

AUDIT LOGGING

Every agent action is logged: what it did, why, and under whose guardrail.

HUMAN APPROVAL

Consequential actions wait for human approval inside guardrails you set; reserved judgment calls reach your team with a recommendation.

PAUSE AT ANY TIME

Agents run on access you grant and can be paused at any time. Any process can be taken back manually.

CONTROLLED DEPLOYMENT

Changes are built and tested in separate environments before they reach production. Nothing ships straight to prod.

Where the boundaries sit.

The diagram below is the delivery model's governance layer: where access is granted, where redaction happens, where approval gates sit, and where the log records it all.

7
CONTROLS, DOCUMENTED
NDA
FULL PACK, DAY ONE
YOURS
CLOUD OR OURS

Your systems
& data

Access you grant · scoped by role

Sensitive data redacted at the boundary

The Kascade layer

AI agents · Run the work

Consequential ↓   ↑ Approved

Our experts · Own the outcome

The record

Every action
every approval
every exception
all logged

Reserved judgment calls → you, with a recommendation

Your cloud or ours. Your review, in parallel.

Kascade deploys in your cloud or ours. The governance model is identical either way. And your security review doesn't gate the timeline: it runs in parallel from day one, so the first agent is in production in four to six weeks while your team completes its diligence with everything it needs.

The full pack, under NDA.

Some material doesn't belong on a public page. Under NDA, your security team gets the complete pack:

SOC 2 Type II report

Data-handling and retention practices

Subprocessor and platform posture

Access-control and redaction configuration detail

Incident-response and escalation procedures

Ask for it on the first call.

Bring your security team to the first call.

Thirty minutes covers the delivery model, the governance boundaries, and what the pack contains, for your operators and your reviewers in the same room.