Note /
What hardened means
Hardened is the word doing the most work on this site. It is not a feature tier or a marketing adjective. It is a specific set of defaults every deployment ships with, and here is what they are.
Least privilege by default
Under the default posture, agents get access to the tools their job needs and nothing else. An agent that chases invoices can read your accounting system; it has no reason to hold keys to anything else, so it does not.
Consequential actions wait for a person
Under the default posture, actions with consequences wait for human sign-off. An agent can prepare the reminder email or stage the update, but nothing with consequences leaves the building on an agent’s own authority.
The posture is written down and signed
Every deployment ends with a signed handover document recording the security posture you chose and what it covers. You are not asked to trust that the deployment is configured sensibly; you are shown what it will and will not do, in writing, and you sign it.
Some deployments we refuse
A deployment configured in a dangerous-equivalent posture, with the guardrails off, is refused outright. That is not a price point and there is no premium that unlocks it. It is a refusal.
What hardening does not remove
Agentic systems carry residual risk, and pretending otherwise would be dishonest. Prompt injection and social engineering exist. Training and guidance are part of every install so this stays unlikely, and the handover document is explicit about where our obligation ends and yours begins. Knowing the edges is part of what you are buying, which is why they are published on the pricing page rather than tucked into small print.