Governance-grade by design

Security posture

Autonomous ops that a CISO can sign off on.

Merchanaut gives the agents autonomy on the floor — inventory, pricing, restock, orders, refunds — and pays for that autonomy with a governance surface that meets mid-market IT and security where they already live: guardrails before every write, an audit trail bound to evidence, encryption in transit and at rest, role-based access gated by the admin plugin, a 24/7 watch over every running agent, and a procurement-ready packet waiting when your security team asks.

1 — Guardrails

PAUSE, audit, and write boundaries on every agent move.

The agents never get the keys directly. Every mutating action — a price change, a restock order, a refund, a supplier PO — crosses a guardrail first. The guardrail fails closed, not log-and-continue, and it is the same gate on every tier. The policies that drive it live on the dashboard — your team reads them, edits them, and audits the changes without an engineer in the loop.

View the policy surface →

  • A gate every agent must cross before mutating catalog, pricing, orders, or supplier POs — fail-closed, not log-and-continue.
  • Write boundaries keyed to the role of the calling agent and the user on whose behalf it acts — no agent writes outside its tier.
  • A Bob-Test pre-flight that repeats its own deterministic check on every pricing move — the policy surface is on the dashboard.

2 — Audit trail

Every decision linked to evidence.

The audit trail is not a log file. Each entry names the agent, the policy version that approved the move, the snapshot it acted on, and the evidence pack it cited. The timeline is replayable — input the same snapshot and the same policy produces the same decision, so a security reviewer can rerun an incident end-to-end without trusting the agent's recollection.

Walk the timeline →

  • Every agent decision binds to the snapshot, the evidence pack, and the policy version that approved it.
  • The timeline on the audit page is replayable — same inputs reproduce the same decision, signed and timestamped.
  • Audit rows are exportable as JSON for downstream SIEM, GRC, or retention storage.

3 — Data handling

Encryption posture, role-based access — no shared passwords.

Every byte that crosses Merchanaut is encrypted in transit and encrypted at rest. Access is scoped per user with the better-auth admin plugin — admin roles gate the settings surface, agent roles gate the write surface, both gates are enforced on the same /api layer the platform ships with. There is no shared admin account, no shared password, and no admin cookie written outside the auth module.

Sovereign deployments isolate per-tenant keys and per-tenant storage before they reach the agent — a regulated retailer runs the same fleet on a private substrate, not a multi-tenant shard.

  • Encryption in transit: TLS 1.3 across every agent↔source and dashboard↔agent hop. HSTS on the marketing and dashboard origins.
  • Encryption at rest: managed application-layer encryption for snapshot, evidence, and decision stores; per-tenant key isolation on sovereign deployments.
  • Role-based access: scoped to per-user data with the better-auth admin plugin — admins gate by role, agents gate by tier, both gates enforced on the same /api surface.
  • Secrets: every third-party credential is short-lived, injected at deploy, never pasted into a config file.

4 — Operational assurance

A 24/7 watch — and the edges where the agent refuses to act.

Autonomy is paid for with attention. The agent-watch layer monitors every running agent — stall, drift, anomalous retries — and escalates to the on-call before any of it reaches a customer. There are also the no-action zones: the catalog edges, the supplier blacklists, the regulated categories, and the pricing floors where the agent is forbidden to act and a named human owns the decision instead.

The same watch runs an anomaly review against the audit trail each week — slow-burn patterns that pass guardrails but should not tick up the human queue anyway.

  • A 24/7 agent-watch layer watches every running agent — stall, drift, and out-of-band retries page the on-call before they reach a customer.
  • No-action zones: the shelf edges and supplier edges where the agent refuses to act and escalates to a named human — pricing floors, regulated categories, and supplier blacklists.
  • Anomaly review: weekly walk of the audit trail for slow-burn patterns that pass guardrails but should not — pricing drift, supplier reply cadence, refund clustering.

5 — Procurement-ready

The packet your IT and security teams ask for.

Mid-market IT and security teams get a packet they can run review against without an in-person meeting. Every item below is in the procurement packet — sent over the contact form on request, with the actual documents and signed artefacts to follow.

Security packet

SOC 2 readiness

The control inventory and evidence map are ready for a Type II review — security, availability, and confidentiality criteria covered.

Security packet

Data residency

Default to US/EU regional deployments; sovereign instances available for retailers with in-country data-residency obligations.

Security packet

DPA + sub-processor list

A signed DPA on request and a current sub-processor list with a 30-day notice window for changes — the same list you sign for the platform contract.

Security packet

Breach-notice SLA

Notification within 72 hours of confirmed incident, with the affected scope, data classes, and remediation timeline in the same message.

Security packet

Pen-test cadence

Annual third-party penetration test of the agent surface and the dashboard — full report under NDA on request.

Security packet

Access reviews

Quarterly reviews of admin-role grants via the admin plugin — every active admin session is attributable to a named user.

Ready when your security team is

Request the security packet — answers in one thread, not a vendor chase.

The same engineer who builds the guardrails takes the call. The procurement packet, the SOC 2 readiness control map, the sub-processor list, the DPA — whichever ones your team is ready to read first, that is what we send first.