Skip to content
Second Key Security

Security and trust

Written for your security team: what our agents can reach, where they run, what happens to your data, and how every change is approved.

Five commitments

  • Runs in your environment

    Agents run in your cloud or on your servers, under your accounts, in a sandbox. Outbound access is limited to your AI model endpoint and the APIs of the systems in scope.

  • Read-only by design

    You create the credentials and the roles, and your own IAM enforces them. We design least-privilege scopes for each service, for example the AWS SecurityAudit policy rather than ReadOnlyAccess, and we prefer short-lived credentials. You can revoke access at any time.

  • Your model, your contract

    Agents use the AI model provider you choose, under your own contract with that provider. Your data stays in your environment and under your provider's terms. We keep only the reports we deliver to you, and delete them on request or when our engagement ends.

  • Nothing changes without your key

    Every change needs your approval. Approved changes run with a separate credential you issue for that change, so we hold no standing write access.

  • Full visibility and a stop button

    Every action is logged in your environment, so you can see exactly what agents read and did. Revoking one account stops everything.

In detail

Access model

You create the credentials and roles. We design least-privilege scopes for each service, for example AWS SecurityAudit rather than ReadOnlyAccess.

Short-lived credentials are preferred wherever your platform supports them.

Where agents run

In your cloud or on your servers, sandboxed. Outbound access is limited to your AI model endpoint and the APIs of the systems in scope.

Data handling

Your data stays in your environment and under your AI model provider's contract with you. We keep only the reports we deliver to you, and delete them on request or when our engagement ends.

Change control

Approved changes run with a separate credential you issue for that change. Every action is logged in your environment.

Our own security

MFA on every account, encrypted devices, and an NDA on request.

Your security questionnaire

For your vendor review.

Email us from your company address and we will answer your security questionnaire.

Email hello@secondkeysecurity.com