Authenticated access
Identity tokens are validated for issuer, audience, signature, subject, issue time, and expiry.
Security and deployment
AutoPilot is designed around authenticated workspaces, tenant-aware data access, bounded AI behavior, human control, auditability, and managed infrastructure.
Sensitive actions should be scoped, reviewed, attributable, and reversible where the workflow allows it.
Architecture principles
Identity tokens are validated for issuer, audience, signature, subject, issue time, and expiry.
Organization context and PostgreSQL row-level security help keep workspace data separated.
Cloud secrets and service access use managed identity and controlled secret storage.
Production data services use private networking and controlled service-to-service access.
Idempotency, replay controls, activity history, capability controls, and operational monitoring support governed change.
AI access and actions are constrained by approved capabilities, roles, tools, and human review.
Current cloud architecture
The current platform uses Cloudflare for the web experience and Microsoft Azure services for identity, application workloads, PostgreSQL, private object storage, secrets, monitoring, and approved AI workloads.
Private cloud or Kubernetes-based on-prem delivery requires a dedicated architecture and support scope covering identity, PostgreSQL, object storage, approved AI services, observability, backups, upgrades, and incident ownership.
A customer-specific design is not the same as an off-the-shelf, self-install, or air-gapped product.
This page describes architecture and control practices. It does not claim SOC 2, ISO 27001, PCI DSS, GDPR certification, independent penetration testing, or regulated banking accreditation. Organization-specific legal, risk, and compliance requirements must be reviewed during an engagement.
We can align a product walkthrough or enterprise discovery around your identity, data, control, integration, and hosting requirements.
Request a security discussion