Build · Steer · Compound

Security & trust for agentic AI evaluators

AI agents as mission-critical systems: scoped tools, department tenancy, policy gates, and continuous evidence — not blanket certifications or shared API keys.

We maintain institutional context within firm boundaries while giving agents the governed access they need to be useful. SOC 2 and HIPAA are readiness programs here — not blanket certifications until your agreement says so.

Substrate:· Methodology: Build · Steer · Compound

This page is the living controls brief — export or screenshot the checklist and compliance path for security questionnaires.

Why agent security is the 2026 bottleneck

We maintain institutional context within firm boundaries while giving agents the governed access they need to be useful. Enterprises treat AI agents as mission-critical, yet most identity stacks still assume human-only principals. OWASP’s LLM and Agentic Top 10 put prompt injection, memory poisoning, excessive agency, and tool misuse at the top of the risk list — I/O Mesh answers with a governed operational context plane, not another chat sandbox.

Non-human identity

Scoped tools and department tenancy — not shared API keys — so agents can act without becoming unaccountable.

Memory tenancy

Optional long-term recall stays department-bound — never a cross-firm vector dump.

Evidence over claims

SOC 2 / HIPAA readiness mappings and continuous gates — attestation only when your agreement says so.

Governed multi-horizon context — not compliance theater

Agent context that compounds across real-time pulses, short-term stream history, and longer analytical or institutional patterns only works when tenancy, policy-gated MCP, and audit lineage sit on the same fabric. I/O Mesh is the governed operational context plane behind the homepage full organizational heartbeat—security is how multi-horizon BI stays usable without claiming blanket certifications.

Full organizational heartbeat: live operations, knowledge memory, and analytics patterns — department-scoped, policy-gated. Security and trust mean department-scoped products agents can use under policy across those horizons, not a checkbox pack that pretends SOC 2 or HIPAA are already signed unless your agreement says so.

Multi-horizon intelligence under policy

The full organizational heartbeat—live ops pulses, knowledge memory of past heartbeats, and analytics patterns—feeds a shared context plane. Agents then work across real-time rates, short-term stream history, and longer analytical or institutional patterns.

Real-time

Live pulse rates and ordered stream state from operational heartbeats agents subscribe to under MCP policy. Incidents, tickets, deploys, pipeline stages, scoped by tenant and department.

Short-term

Hours to days of stream history and rolling operational context. Lineage agents can cite. Do not invent 1h/24h/7d product windows.

Long-term

Analytical history and institutional patterns under tenancy and audit controls.

The full organizational heartbeat — three connected signals

One fabric, three signals: live operations, knowledge, and analytics — department-scoped, policy-gated.

Live operations

Tickets, incidents, deploys, and customer updates, organized by team. The primary heartbeat a reviewer can see after a source, a stream, and a signed event.

Knowledge

Docs, runbooks, and memory of past heartbeats. What previous activity meant. Reviewers can open this layer in the product; do not chip it as a readiness label.

Analytics

Patterns and trends across heartbeats so agents see beyond the moment. Same rule: describe the layer, do not chip a status.

No SOC 2 Type II claim on this page. HIPAA is a readiness mapping, not a certification. A BAA is required before PHI.

Secure payment · Immediate full access · 15% off annual

Control layers on I/O Mesh

Product surfaces platform teams can staff and measure — mapped to Build · Steer · Compound Build (tools + gates), Steer (portal context + memory), and Compound (usage proof + private evals).

Tenancy & isolation

Prevent context bleed while enabling multi-dept agents — org → workspace → tenant with dept.* namespaces, not a shared agent memory bucket.

  • Department-scoped publish enforces tenant isolation at ingress
  • Plan gates on memory, Kafka mappings, connectors, and MCP invoke
  • No cross-tenant shared memory indexes — Palace roots collocate with tenancy
  • Chaos isolation tests on cross-tenant publish/recall paths

Identity & access

Treat human and non-human principals differently — sessions, SSO/SCIM, and audited privilege elevation so support is powerful without being unaccountable.

  • Portal sessions with HttpOnly / SameSite cookies (OIDC-ready)
  • SSO + SCIM provisioning with org/workspace hierarchy (Compliance add-on)
  • IdP group → dept.* subject scope sync for department ACL fidelity
  • Support impersonation requires privileged role; start/end audit pairs

Agentic TRiSM & MCP governance

Stop free-form agent tools from becoming production risk — policy-gated, rate-limited, department-scoped MCP with preflight and audit.

  • MCP tools scoped to department tenancy with policy preflight on every call
  • Rego/OPA policy bundles and mesh policy preview before save
  • Rate limits + plan entitlements on tool invoke (prompt injection / misuse controls by design)
  • Governance add-on: visual policy editor, field ABAC, federation audit exports

Encryption & data handling

Protect operational facts as token capital — in transit, at rest, and under customer-controlled key policy when required (enterprise BYOK path).

  • TLS in transit for broker and control-plane APIs (min TLS 1.2+; TLS 1.3 preferred)
  • At-rest encryption for object storage sinks
  • Enterprise KMS envelope encryption path with customer BYOK policy
  • Connector webhook HMAC verification — failed verifies isolated, not silent

Audit, lineage & observability

Give evaluators request-level truth — who published, who invoked, what enriched, and what support did — so GRC reviews are evidence-backed.

  • Impersonation start/end pairs exportable for GRC review
  • Publish lineage through enrich → memory advisories
  • Usage meters for publish, memory ingest, and MCP invoke (Compound loop proof)
  • Security headers on portal/admin surfaces; control-plane HSTS / nosniff middleware

Secure development & supply chain

Inherit continuous gates instead of a one-time PDF — SAST, dependency, container SBOM, and optional DAST on the release path.

  • Go SAST + govulncheck + staticcheck on every security-scan gate
  • pnpm audit for portal/admin frontends; fail on high/critical
  • Container image Trivy + SBOM (syft) + Grype on foundation images
  • OWASP ZAP baseline available against broker/control-plane/portal origins

Buyer checklist map

How common 2026 agentic risk classes land on I/O Mesh controls — for security questionnaires, not as a certification claim.

Risk classI/O Mesh controlSurface
Prompt injection / tool hijackPolicy-gated MCP invoke + subject ACLs at ingressMCP tools · mesh policy preview
Memory poisoning / context bleedDepartment-scoped memory chambers; no cross-tenant indexesDepartment-scoped memory chambers. No cross-tenant indexes.
Excessive agencyPlan entitlements, rate limits, dry-run validation on automation pathsEntitlements · automation studio
Shadow tools / sprawlCataloged dept.* products + governed connectors with OAuth/HMACIntegrations · data products
Privileged support abuseRole-gated impersonation with paired audit eventsAdmin console audit
Vulnerable componentsgovulncheck, Trivy, SBOM/Grype, pnpm audit in release gatesCI security-scan

Compliance readiness — not claims

Readiness mappings and commercial packs for regulated evaluators. We do not claim SOC 2 Type II or a signed BAA on this page.

SOC 2 Type II path

Readiness mapping

Mapped to AICPA Trust Services Criteria with readiness artifacts (access, tenancy, monitoring, change gates). Control mapping is a readiness artifact — not an auditor report until Type II is issued under your commercial path.

HIPAA Security Rule mapping

Readiness mapping

Administrative and technical safeguards mapped for care-adjacent B2B workloads. BAA required for PHI handling — marketing packs do not replace a signed BAA.

Compliance add-on

Commercial add-on

SSO/SCIM automation, IdP scope sync, dedicated compliance reviewer path, and evidence-pack packaging for enterprise evaluators.

Governance add-on

Commercial add-on

Visual Rego editor, field-level ABAC, traffic analytics, and federation audit exports for regulated mesh operators.

Continuous security program

Engineering program

Continuous gates (SAST, dependency scans, container SBOM/Grype, optional OWASP ZAP DAST) and chaos isolation tests so you inherit production-grade controls — not a one-time PDF.

Availability & status

A dedicated public status page is the next polish for platform teams who want subscribe-to-incident feeds without a sales ticket. Production edge and self-serve Base plan are live today — start in the console, or email hello@iome.sh for availability questions.

Create a workspace →

I/O Mesh security — governed context without sacrificing usefulness

We solve the agent security problem the same way platform teams solved service security: clear boundaries, policy enforcement, and evidence over promises.

Tenancy, identity, encryption, audit, and compliance readiness are built into the fabric — so your AI agents can be powerful without becoming a liability.

Controls are built into the product fabric — giving you audit-friendly evidence paths from day one without waiting on a separate security product.

Ready to evaluate the security model for your environment?

Get started in the console, or review Governance and Compliance packs on Pricing. Use the buyer checklist as the questionnaire map.

  • Department tenancy
  • KMS BYOK path
  • SOC 2 / HIPAA readiness
  • Open-source components on GitHub

Policy gates · audit trails · continuous security-scan gates