Scoped execution
Organizations are the tenant boundary. Runs, traces, settings, keys, credentials, workflows, and approvals are tenant-scoped; app, agent, and subject identifiers further attribute activity.
// trust center · reviewed 2026-07-20
Punk is an adaptive runtime for AI agents. This center separates implemented product controls, customer-configurable deployment choices, unavailable or unverified items, and topics that need contractual review.
This is a product posture summary, not a certification, legal commitment, or customer-specific security addendum. Review the actual deployment and configured providers before relying on a control.
// current product controls
These describe product behavior documented for the current runtime. Some require deployment configuration to be effective.
Organizations are the tenant boundary. Runs, traces, settings, keys, credentials, workflows, and approvals are tenant-scoped; app, agent, and subject identifiers further attribute activity.
Run evidence includes route explanations and a per-run trace-integrity hash chain. Artifact promotion requires replay and shadow evidence; rollback and quarantine controls are part of the runtime lifecycle.
Tenant API keys, sessions, and one-time tokens are stored as hashes. Stored credential secrets use AES-256-GCM when a valid PUNK_ENCRYPTION_KEY is configured before storage.
Tools have side-effect levels 0–4. Undeclared tools default to level 3, a user-visible write. Replay and shadow are designed to suppress side effects.
Trace retention defaults to 90 days unless a tenant setting or job override applies. Stored trace redaction can deterministically mask string leaves before append.
Run detail, audit, readiness, integrity, and evidence-packet endpoints support a deployment review. The public status page reports a live health signal.
// customer-configurable
| Setting or choice | What it changes | Review action |
|---|---|---|
| Retention | Tenant retention can override the default 90-day sweep window. | Confirm retention, backups, and evidence-export needs before production traffic. |
| Trace redaction and streaming DLP | Redaction masks stored trace strings; streaming DLP masks supported sensitive patterns in returned bytes. | Enable and test against the customer workload; both affect evidence fidelity or output readability. |
| Learning and cache posture | Semantic cache, model substitution, and cross-tenant aggregate learning are tenant settings. | Start in observe mode and do not enable cross-tenant aggregate learning without explicit opt-in. |
| Provider and credentials | Hosted provider configuration or tenant BYOK can serve live traffic. | Review each configured provider's own data, retention, training, DPA, and subprocessor terms. |
| Side-effect policy | Policies and approvals govern tool actions. | Keep level 3 and 4 tools approval-required or denied for an initial pilot. |
// unavailable or unverified
No completed SOC 2, ISO 27001, HIPAA, or other formal compliance attestation is claimed here.
SSO, SAML, and SCIM are not claimed without separate implementation and evidence.
No public SLA, incident-notification SLA, data-residency promise, BAA, customer-managed key support, or database-level row-security commitment is offered here.
A public subprocessor list is not currently published. Live provider exposure must be reviewed for the selected configuration.
Credential encryption is documented; database, disk, backup, provider, and edge-encryption posture remains deployment-specific evidence.
A public DPA, BAA, or signed customer agreement is not represented by this site. Those requests require separate review.
For an enterprise review, start with a readiness receipt, sample evidence packet, relevant policies, tenant settings, enabled connectors, provider-key source, and backup or incident evidence.