Security and data
A provenance system holds the most sensitive record an engineering organisation has: what everyone did, when, and on whose authority. These are the commitments that come with holding it.
Your perimeter, your data
Self-hosted deployment is first-class: Topos runs inside your infrastructure, and the ledger never leaves it. A managed option exists for institutions that prefer it, with data residency configured per engagement. In both models the audit ledger belongs to the institution and is readable directly by your own risk, audit and security functions through a typed API. There is no aggregation of customer data across institutions.
No training on your data
Topos governs AI agents; it is not in the business of feeding them. Nothing an institution's deployment records is used to train models, ours or anyone's. The AI services an engagement uses are chosen and contracted per institution, inside the institution's own compliance envelope.
Evidence that cannot be quietly edited
The ledger is append-only and hash-chained: records are never updated in place, and alteration is detectable. Views and reports are derived from it and can be rebuilt from it, so there is no second copy to drift. Offsite copies are written to storage the writing credential cannot delete from, so a compromised machine cannot destroy its own history. Corrections happen the way they do in bookkeeping: a new entry that supersedes an old one, with both preserved.
Authority is narrow by construction
Operators sign policy acts; machines sign facts. Agents run with least privilege, the rules they work under are locked against them, and changing enforcement machinery requires a named human's signed approval, checked mechanically. When our own audits find gaps in these locks, and they have, the findings are recorded, fixed in the open, and published in the essays rather than buried. We would rather you learn our failure modes from us.
Observation the agent cannot opt out of
In research: a kernel-level observation plane, using eBPF, that records what agent processes actually do at the system-call level, independently of what they report about themselves. Two observation planes that check each other make the record stronger than either alone; where they disagree, the disagreement is investigated as a finding. We say "in research" because it is; this page does not describe shipped capability it does not have.
Jurisdiction
OctoView Labs AB is a Swedish company (org.nr 559585-3119, Stockholm) operating under Swedish and EU law. Engagements with regulated institutions are structured to fit the institution's own regulatory obligations, including data protection and outsourcing requirements, and we expect to be audited by our customers.
Disclosure
Security concerns or suspected vulnerabilities in anything we operate: contact@octoviewlabs.com, and put "security" in the subject line. A person reads it.