SECURITY

Security for AI that takes action

ACE reviews code, changes software, analyzes logs, and touches infrastructure. Security was designed for this level of action.

  • Isolated, temporary workspaces for each task
  • Least-privilege credentials issued on demand
  • Policy outside the AI model, with approval and audit

Agent access

Secrets vault

Masked

AWS_SECRET_ACCESS_KEY

••••••••
staging · read15 min

GITHUB_TOKEN

••••••••
1 repo · pull request20 min

DATABASE_URL

••••••••
replica · read-only10 min

KUBE_CONFIG

••••••••
1 namespace · logs5 min

SECURITY MODEL

Four controls before any action

ACE combines isolation, encryption, temporary access, and least privilege to reduce operational risk.

Data protected by design

Source code, configuration, artifacts, and operational data are encrypted in transit and at rest.

  • Keys managed separately
  • Data available only for the task

Isolated, temporary execution

Each task runs in a dedicated workspace, separated by customer, project, and environment.

  • Workspace destroyed at completion
  • No reusable snapshots with customer data

No permanent credentials

ACE does not place long-lived cloud or repository credentials inside an agent workspace.

  • Access issued on demand
  • Automatic expiration or revocation

Least privilege by operation

Every action is limited by customer, project, repository, environment, permitted operation, and time.

  • Read-only first when possible
  • Production separated from development

HOW AN ACTION IS CLEARED

From request to revocation

The AI can suggest. Execution only happens after passing the platform-defined boundaries.

Stage 1 of 5

The agent proposes an action

Intent, user, agent, project, and target are identified before execution starts.

Scope

Identified

Permission

Requested

Environment

Declared
Progress1/5

HUMAN CONTROL

Approval when it matters. Audit always.

You choose what runs automatically and what pauses for review before touching production, cloud, or security.

Approval

Sensitive actions stop first

Rules by environment, change type, and risk define what can run on its own and what requires human approval. That is how fixing a bug in production happens with scope, approval, and isolation.

ACE DEV wants to run

terraform apply · production

Review
ApproveReject
  • Production deploy
  • Infrastructure change
  • Destructive command
  • Security change

Audit

Every run becomes a record

Logs connect the user, agent, ticket, project, environment, tool used, approval, and operation result.

01Who requested it
02Which agent ran it
03What access was granted
04What changed
05When it was revoked

Secrets

Secrets stay secret

Passwords, API keys, cloud credentials, and tokens go only to the approved operation that needs them, and stay masked in agent-visible output.

Source codePromptsCommand historyProcess argumentsBuild artifactsScreenshotsAgent responsesLogs

ENTERPRISE READY

Compliance, blast radius, and accountability

ACE controls are designed for AI connected to code, cloud, logs, and real environments.

Compliance

A program designed for organizations handling sensitive technical and operational data.

SOC 2HIPAAIAMSecure development

Fault isolation

If a task, dependency, or external input fails, the failure stays inside that task's scope.

Task isolationZero lateral accessScoped productionSession cleanup

Accountability

Beyond technical controls, EZOps maintains operational coverage for enterprise customers.

Tech E&OCyber LiabilityIncident responseControl reviews

Your systems remain under your control

Join the list and see how ACE performs real work without giving up isolation, policy, approval, and audit.

Leave your email and we'll let you know as soon as sign-up opens for new users.