Security
How Symmi protects your company.
For your IT and security team: the controls that protect your data, your agents and your decisions. The detail of each control in your implementation comes with the security questionnaire.
Updated September 24, 2026
What an agent can do
Four layers, and each can only be stricter than the one around it.
Four permission layers
Symmi's floor, your company's policy, the agent's limits and trust per action. Forbidden in any layer wins.
The approval gate is in the code
An action that needs approval stays stopped until someone approves it. The agent never approves sensitive actions (code, permissions, configuration), or anything the person hasn't seen yet.
A person grants trust, and it drops on its own
Every action starts at Asks first. Only an admin raises it, never above the company ceiling, and if it fails or someone rejects it, it goes back to Asks first.
Budgets with a ceiling
Every agent has a budget: it warns at 75% and 90%, and stops at 100%.
Named approvers, enforced
Only the people named on the agent can give each approval.
Second factor by amount
Above the amount your company sets, approving asks for a second factor.
What comes from outside
An email, a document or a web page doesn't give an agent orders.
Outside content arrives marked
Everything a tool returns reaches the model marked as untrusted data, and is scanned for injected instructions, hidden text and look-alike letters.
With outside content in view, it asks again
If the agent has something from outside in its context, actions it would take on its own go back to asking for approval.
Replies without secrets
Every reply is checked before it goes out, and blocked if it carries a token or a key.
Tests and shadow runs with no effects
While the judge tests an agent or it runs in shadow, its writes are recorded instead of executed.
Every company, separate
Your data never mixes with another company's, and we test it against production.
Separation per company, in code
Data, memory, tools, connections and background jobs are filtered by company in every query. The database gives nothing to the app's public key.
Isolation suite against production
Two test companies try to read and write into each other in production, with a second factor. The last run, on September 23, passed 92 of 92.
Private personal accounts
The accounts each person connects are used only by their own agents; neither IT nor Symmi's team can read them.
Encryption keys per company
Every company has its own key to encrypt its data.
Who gets in, and what they can do
No one gets in without being on their company's list, and no one gets in without a second factor.
No passwords
Every sign-in uses a one-time code or link, and every session is verified by its signature.
Second factor required
TOTP to get in. Without a second factor, the API doesn't answer.
An access list that fails closed
If you're not on the list, or the list can't be read, you don't get in.
Roles
Viewer, operator and admin. Viewers change nothing; only an admin changes policy, grants trust or exports the record.
SSO and SCIM
Sign-in with Entra ID, Google Workspace or Okta (SAML or OIDC), and people provisioned by SCIM.
A record of everything
What happened, who did it and when, visible to your company.
Security events per company
Detected injections, forbidden actions, escalations and policy changes, with severity. Only an admin marks them reviewed.
Policy changes with author and reason
Every change keeps what it was, what it became, who made it, with what role and why.
Who approved each action
Every approval keeps who gave it and when.
Export the record
An admin downloads up to 365 days as CSV or JSON, and the export is recorded too.
Streaming to your SIEM
The record reaches your SIEM live.
Retention on your terms
Your company chooses how long the record is kept.
Where your data lives
In the western United States, in the region you choose, or on your own servers.
Database
A managed database in the western United States.
Application
A managed cloud in the US West region.
HTTPS for all traffic
Every connection to Symmi is encrypted with TLS.
Encryption at rest
The database is encrypted at rest (AES-256).
Database backups
Automatic database backups, every day.
Credentials
Tokens Symmi stores are encrypted in the application with a rotatable key. OAuth access to your apps is held by a connections provider, not by Symmi.
Choose the region
Your company chooses the region its data lives in.
On your servers, with your keys
The same Symmi installed on your infrastructure, with your own API keys.
Delete or export everything
An admin deletes or exports all of the company's data from the console.
Logs without customer content
Technical logs don't keep message fragments or email addresses.
The AI models
The model is just another provider, and your company chooses which ones are used.
A pool of providers
Several providers, through their APIs. Symmi picks the model for each step from the ones your company allows, and memory uses one of them for embeddings.
Allowed providers per company
Your company chooses which providers may be used.
Zero retention at the providers
Zero data retention agreements with the providers that offer them.
Subprocessors
The services that touch your company's data: what they do, what data they see and where.
| Service | What data | Where |
|---|---|---|
| Application cloud | Everything Symmi processes | US (West) |
| Database, sign-in and files | All of your company's data | US (West) |
| AI models, the ones your company allows | The context of each step and the text of the memory | By provider: US, China or global |
| Connections to your apps (OAuth) | What the agent sends to and receives from each app | US |
| Isolated environments for code | Code and repository tokens | — |
| Code repositories, if you connect them | Code | US |
| Web search | Search queries | — |
| Images and video | Creative requests and files | US |
| Notices in the browser and on the phone | Title and text of each notice | Depends on your browser |
Each provider's name, contract and region are in the data processing agreement we sign with you.
Certifications and documents
What we sign with every customer, and the audits in progress.
Security questionnaires
We answer them with this page and the architecture.
Data processing agreement
We sign a data processing agreement with every customer.
SOC 2 and ISO 27001, in progress
External audits of our controls.
External penetration tests, in progress
An outside team attacks Symmi, and we share the summary with every customer.
Found a security problem?
Tell us through the form. A person from the team will answer, and we'll tell you when it's fixed.
Report a problem