Skip to content
Security & trust

Trust you can verify, and revoke.

Every security SaaS asks you to trust it with your data. Alyria is built so you can check instead: fleet data and audit records are encrypted under an envelope key we delete on request: a permanent crypto-shred. Enterprises can bring their own KMS key, revoke it, and watch our access die in their own CloudTrail. The claim is verifiable, not promised.

Free. Read-only. Remove it with one command.

Under your keys
an envelope key we delete, or your own KMS key you revoke
One audit chain
signed, tamper-evident, end to end
Open-core roadmap
client crypto published and externally audited as it ships
Under your keys

Encrypted by default. Cut us off, verifiably.

Trust, verifiable. Enterprises can bring their own KMS key: hold it, revoke it, and watch our access die in their own CloudTrail. By default, fleet data and the audit chain are encrypted under an envelope key we delete on account termination or request, and static blobs stored with us are opaque to us at rest. That is a claim you can drill, not one you take on faith.

Umbra — secrets under your keys; the roadmap is keys we never hold. See the module →

Encrypted by default

Fleet data and the audit chain are encrypted under an envelope key we hold and delete on account termination or request, which makes them permanently unreadable, a crypto-shred. Static blobs stored with us are opaque to us at rest, and there is nothing to configure.

Bring your own key, for enterprise

Regulated and large fleets can bring their own KMS key (BYOK), or hold a key they never share with us (HYOK). Alyria operates only with the access you grant, and every use of the key is logged on your side.

The kill-switch drill

Every pilot includes the drill, and it works either way: we delete our envelope key, or you revoke your own BYOK key and watch our access die in your own CloudTrail. It is the standing arrangement, not a demo trick.

Roadmap: keys we never hold

Umbra moves custody further: client-held keys with a published, externally audited protocol, so the broker only ever moves ciphertext. We make that claim when you can check it, not before.

Auditability

Trust that’s verifiable, not asserted.

A custody claim is only as good as your ability to check it, which is why every pilot includes the kill-switch drill. The rest is built to the same standard: the audit chain is signed, the endpoint agent is reproducible, and the client crypto carves out to open source as it ships.

Open, auditable client crypto

Umbra's client crypto and protocol carve out to open source (Apache/MPL) so anyone can verify the client-side crypto end to end when it ships, a claim you can read, not take on faith.

Open-core & licensing

One signed audit chain

Every policy decision and detection writes to a single append-only, cryptographically signed log: one source of truth spanning APG and ADR, legible to auditors and adversaries alike.

Tamper-evidence

The audit chain is hash-linked and signed, so any gap, reorder, or edit is detectable after the fact. Stream it to Observatory or straight into your own Elastic/Kibana SIEM.

Signed & reproducible builds

Beacon is built to ship signed, with reproducible builds on the guarantees roadmap, so you can confirm the binary on your fleet is the code that was reviewed.

Standards anchor

OWASP ASI for what attackers do. NIST & ISO for how you govern it.

One signed audit chain covers both — the adversarial story and the compliance story from a single source of truth, so the two can never drift.

OWASP Agentic Top-10 — what attackers do
  • ASI02
    Tool misuse
    brokered, policy-checked MCP calls
  • ASI03
    Identity & privilege
    capabilities scoped to the IdP identity
  • ASI04
    Supply chain
    MCP posture and tool pinning
  • ASI05
    Unexpected code execution
    user-space runtime observation
  • ASI07
    Inter-agent comms
    activity recorded under your keys
Governance frameworks — how you govern it
  • NIST AI RMF
    Map / Measure / Manage / Govern — the risk-management spine US enterprises align to.
  • ISO/IEC 42001
    The AI management-system standard your auditors and procurement teams ask for by number.
  • EU AI Act
    Risk-tiered obligations for AI systems — the regulatory anchor for governance buyers.

One chain, both audiences. The same signed log that proves an ASI05 code-execution block to a red team is the evidence that satisfies a 42001 audit — no second system, no reconciliation.

Security guarantees

A paid tier — independent of your license.

The architecture is under-your-keys for everyone. Guarantees are a distinct commercial tier: the signed attestations, SLAs, and response commitments a regulated buyer needs — available with the hosted cloud today, and with self-hosted builds as they open up.

Talk to us about guarantees
  • Signed & reproducible builds

    Verifiable artifacts across the fleet.

  • SLA

    Contractual uptime and support-response commitments.

  • Warranty & indemnity

    We stand behind the product commercially.

  • SOC 2 + pen-test attestations

    Independent attestations as they complete, shared under NDA.

  • CVE response windows

    Committed timelines to triage and patch.

Open core & licensing
Roadmap · coming soon

The open-core playbook.

This is the licensing plan as the platform opens up, deliberately and never the reverse: open where it must be auditable, source-available where it protects the business, closed where it’s the commercial core. Today the platform is closed while we harden it; the tiers below are the intended end-state, not yet published.

OpenApache-2.0 / MPL-2.0

Umbra client-side crypto & SDK

The parts that must be auditable for the under-your-keys claim to be credible will carve out to open source: client crypto, the A2A protocol, and the SDK, published as they ship.

  • Verifiable by anyone
  • The community on-ramp
  • Published under owpz
Source-availableBSL 1.1

The platform bulk

Constellation server, Beacon core, Lyra, and Spectra will ship source-available: free to run, read, and modify, converting to open source on a time delay.

  • Source you can audit before you deploy
  • Free except a competing hosted service
  • Auto-converts to OSS over time
ClosedProprietary

Observatory & the broker

The hosted Alyria Cloud console, the Umbra broker service, and enterprise features stay proprietary: the commercial core.

  • Observatory / Alyria Cloud
  • Umbra broker service
  • SSO/SCIM, RBAC, fleet mgmt

Security guarantees — signed builds, SLA, warranty/indemnity, SOC 2 + pen-test attestations, CVE response windows — are a paid tier that sits independent of any license above.

Responsible disclosure

Found something? Tell us.

We welcome coordinated disclosure and will work with you in good faith. Report vulnerabilities to our security team and see our published policy and contact key.

Please do not disclose publicly until we’ve confirmed a fix. We aim to acknowledge reports promptly and keep you updated through remediation.

See the model, then audit the claim.

Walk through the kill-switch drill and the audit chain with our team, or read how key custody, audit, and enforcement fit together.

Free. Read-only. Remove it with one command.