Trust · architecture and assurance

Authority should survive scrutiny.

Lagstyr is being built so consequential agent work remains explainable, bounded, verifiable, and owned by the company—including when the model is wrong, evidence is absent, or the vendor is unreachable.

Load-bearing commitments

Control is architectural, not a policy paragraph.

These principles shape the product design and are exercised in the implemented foundation. Their current evidence standing is recorded below.

One narrow gateway for consequential action

An AI agent can never change a real system directly. Every change passes through a gateway that checks it against policy—the action’s exact shape, its limits, and its approvers are fixed by the company, and the agent cannot choose its own risk tier or its own approvers.

Stable identity and provenance

Company records preserve the entity, source, actor, causation, correlation, history, and confidence needed to reconstruct why work happened.

Verified effect

An accepted proposal is not proof of success. Idempotency, receipts, readback, and reconciliation establish what the owning system actually did.

Governed self-change

Prompts, models, skills, schemas, policy, rubrics, and governance change through proposal and approval. No agent silently expands its own powers.

Documents are read inside the installation

Scanned pages are read by text-recognition (OCR) software that ships inside your installation—a fixed, known version. Nothing is sent to an outside service and nothing is downloaded at run time. Every page records how it was read: embedded text, OCR, or explicitly unreadable.

Absence is never success

Missing effects or measurements remain not configured or need attention. Released minutes are not converted into money, and financial value is not inferred from activity or prose.

Customer-controlled runtime

The intended BYOC model isolates by deployment. The company record remains in infrastructure the customer controls, rather than a vendor multi-tenant data plane.

No vendor on the authority path

No licence check, vendor heartbeat, mandatory telemetry, vendor-held runtime credential, or inbound management endpoint is intended to block company operation.

System boundaries

Specialist systems keep specialist truth.

Lagstyr does not claim authority it should not own. The ledger remains authoritative for accounting; payroll for pay; CRM for pipeline; repositories for code. Lagstyr holds the management record that connects their work.

Lagstyr authority

Management context

Mandates, evidence, decisions, approvals, obligations, agent actions, effects, conflicts, measures, and outcomes.

External authority

Specialist facts

Accounts, payroll, customer pipeline, purchase orders, payments, communications, code, deployments, and tickets remain with their owning systems.

Derived, never sacred

Rebuildable views

Search indexes, summaries, and model outputs can always be rebuilt. They never silently outrank the authoritative records they were derived from.

Current assurance position

Strong internal discipline. No borrowed badges.

Behind the build sit more than 4,500 automated tests, deliberate fault-injection (mutation) testing with a written disposition ledger, isolated end-to-end launch rehearsals, security-oriented design gates, and a release gate with named human approvers. That is real discipline—and it is not the same as customer or independent assurance, so we label the difference.

In place

Engineering assurance

Deterministic contracts, paths that refuse rather than guess when checks fail, least-authority boundaries between components, security checks in the build pipeline, and dated evidence documents for drills and rehearsals.

Lab evidence

Document and supplier-renewal proof

A reproducible, licensed synthetic test set exercises bounded indexing, in-installation OCR, extraction with exact source passages, human-only promotion to record, and explicit refusal states. It is our own test data, run by us.

Built, not yet proven live

Deployment evidence

A provisioned installation, restore and failure drills in that environment, observed capacity, support operation, upgrade evidence, and live end-to-end integration proof.

Not available

Independent certification

No independent penetration test, SOC 2 report, ISO/IEC 27001 certification, ISO/IEC 42001 certification, formal high-availability claim, or production customer reference.

Security claims will be updated when evidence changes. Until then, this page is intentionally narrower than the product ambition.

Report a security concern.

Our security page explains where to send a report, what is in scope today, what happens next, and our good-faith research commitment.

How to report