Enterprise
The security review is the sales process.
For a product that governs agents, the review is the evaluation — and most of ours is answered by the deployment model rather than by a questionnaire. You do not send us data, so most of the questions do not apply, and we would rather say which ones remain.
What an enterprise deployment includes
- Single tenant, your environment
- Your VPC, your data centre, or airgapped. Not a namespace in a shared cluster with a residency label attached.
- Your identity provider
- OIDC. Identity, groups and multi-factor policy stay with your IdP, and RotaGrant maps them to what they grant here. It stores no credentials.
- Your keys
- KMS, HSM, or external custody where we cannot sign without you.
- Your regimes
- Market profiles per workspace or per agent, resolved narrowest-first, so a group operating in several markets does not need one configuration that fits none of them.
- Deployment support
- We help you stand it up and integrate the first agents. That is engineering support for software you run — not a consulting engagement.
What a review actually needs from us
An architecture diagram, the egress inventory, the key custody model, and a completed questionnaire — all of which we keep ready rather than assembling per deal. Our certification position is on the trust page.
Take it with you
What runs where, what can leave, what we hold and what we do not — including the certifications we do not have. Download.
What a design partner gets, what we ask in return, and what it costs. Download.
A completed security questionnaire, the egress inventory and the architecture are kept ready rather than assembled per deal — ask [email protected] and they arrive the same day.