Security

How Symmi protects your company.

For your IT and security team: the controls that protect your data, your agents and your decisions. The detail of each control in your implementation comes with the security questionnaire.

Updated September 24, 2026

What an agent can do

Four layers, and each can only be stricter than the one around it.

  • Four permission layers

    Symmi's floor, your company's policy, the agent's limits and trust per action. Forbidden in any layer wins.

  • The approval gate is in the code

    An action that needs approval stays stopped until someone approves it. The agent never approves sensitive actions (code, permissions, configuration), or anything the person hasn't seen yet.

  • A person grants trust, and it drops on its own

    Every action starts at Asks first. Only an admin raises it, never above the company ceiling, and if it fails or someone rejects it, it goes back to Asks first.

  • Budgets with a ceiling

    Every agent has a budget: it warns at 75% and 90%, and stops at 100%.

  • Named approvers, enforced

    Only the people named on the agent can give each approval.

  • Second factor by amount

    Above the amount your company sets, approving asks for a second factor.

What comes from outside

An email, a document or a web page doesn't give an agent orders.

  • Outside content arrives marked

    Everything a tool returns reaches the model marked as untrusted data, and is scanned for injected instructions, hidden text and look-alike letters.

  • With outside content in view, it asks again

    If the agent has something from outside in its context, actions it would take on its own go back to asking for approval.

  • Replies without secrets

    Every reply is checked before it goes out, and blocked if it carries a token or a key.

  • Tests and shadow runs with no effects

    While the judge tests an agent or it runs in shadow, its writes are recorded instead of executed.

Every company, separate

Your data never mixes with another company's, and we test it against production.

  • Separation per company, in code

    Data, memory, tools, connections and background jobs are filtered by company in every query. The database gives nothing to the app's public key.

  • Isolation suite against production

    Two test companies try to read and write into each other in production, with a second factor. The last run, on September 23, passed 92 of 92.

  • Private personal accounts

    The accounts each person connects are used only by their own agents; neither IT nor Symmi's team can read them.

  • Encryption keys per company

    Every company has its own key to encrypt its data.

Who gets in, and what they can do

No one gets in without being on their company's list, and no one gets in without a second factor.

  • No passwords

    Every sign-in uses a one-time code or link, and every session is verified by its signature.

  • Second factor required

    TOTP to get in. Without a second factor, the API doesn't answer.

  • An access list that fails closed

    If you're not on the list, or the list can't be read, you don't get in.

  • Roles

    Viewer, operator and admin. Viewers change nothing; only an admin changes policy, grants trust or exports the record.

  • SSO and SCIM

    Sign-in with Entra ID, Google Workspace or Okta (SAML or OIDC), and people provisioned by SCIM.

A record of everything

What happened, who did it and when, visible to your company.

  • Security events per company

    Detected injections, forbidden actions, escalations and policy changes, with severity. Only an admin marks them reviewed.

  • Policy changes with author and reason

    Every change keeps what it was, what it became, who made it, with what role and why.

  • Who approved each action

    Every approval keeps who gave it and when.

  • Export the record

    An admin downloads up to 365 days as CSV or JSON, and the export is recorded too.

  • Streaming to your SIEM

    The record reaches your SIEM live.

  • Retention on your terms

    Your company chooses how long the record is kept.

Where your data lives

In the western United States, in the region you choose, or on your own servers.

  • Database

    A managed database in the western United States.

  • Application

    A managed cloud in the US West region.

  • HTTPS for all traffic

    Every connection to Symmi is encrypted with TLS.

  • Encryption at rest

    The database is encrypted at rest (AES-256).

  • Database backups

    Automatic database backups, every day.

  • Credentials

    Tokens Symmi stores are encrypted in the application with a rotatable key. OAuth access to your apps is held by a connections provider, not by Symmi.

  • Choose the region

    Your company chooses the region its data lives in.

  • On your servers, with your keys

    The same Symmi installed on your infrastructure, with your own API keys.

  • Delete or export everything

    An admin deletes or exports all of the company's data from the console.

  • Logs without customer content

    Technical logs don't keep message fragments or email addresses.

The AI models

The model is just another provider, and your company chooses which ones are used.

  • A pool of providers

    Several providers, through their APIs. Symmi picks the model for each step from the ones your company allows, and memory uses one of them for embeddings.

  • Allowed providers per company

    Your company chooses which providers may be used.

  • Zero retention at the providers

    Zero data retention agreements with the providers that offer them.

Subprocessors

The services that touch your company's data: what they do, what data they see and where.

ServiceWhat dataWhere
Application cloudEverything Symmi processesUS (West)
Database, sign-in and filesAll of your company's dataUS (West)
AI models, the ones your company allowsThe context of each step and the text of the memoryBy provider: US, China or global
Connections to your apps (OAuth)What the agent sends to and receives from each appUS
Isolated environments for codeCode and repository tokens—
Code repositories, if you connect themCodeUS
Web searchSearch queries—
Images and videoCreative requests and filesUS
Notices in the browser and on the phoneTitle and text of each noticeDepends on your browser

Each provider's name, contract and region are in the data processing agreement we sign with you.

Certifications and documents

What we sign with every customer, and the audits in progress.

  • Security questionnaires

    We answer them with this page and the architecture.

  • Data processing agreement

    We sign a data processing agreement with every customer.

  • SOC 2 and ISO 27001, in progress

    External audits of our controls.

  • External penetration tests, in progress

    An outside team attacks Symmi, and we share the summary with every customer.

Found a security problem?

Tell us through the form. A person from the team will answer, and we'll tell you when it's fixed.

Report a problem