Security
Security answers
The questions a security review or an auditor asks, answered one by one.
In development. Early access open for regulated teams in the UAE and Qatar.
The questions a security review or an auditor asks, answered plainly. Firmantia is in development: where an answer describes how it is built to run for a customer rather than something running today, it says so.
1. What data does it create, and where is it stored
Records of what AI agents did, read from the agent platform's own audit export: the agent, the action, the tool or model called, the policy decision, the time, the platform's reference for the event, and SHA-256 hashes of input and output where the platform exports them. Each record is stored once, append only, in a PostgreSQL database the customer runs. Records are sealed into signed, chained, time stamped batches. An evidence pack is one file exported from that database.
2. What leaves the boundary
The SHA-256 hash of each sealed batch, sent to an RFC 3161 time stamp authority. Nothing else. No record, no content and no key leaves. The demo uses DigiCert's public time stamp authority; an in-country authority is a configuration change once one is designated. Public transparency logs are supported as an option and are off by default.
3. Who can read the record
Whoever the customer gives access to the database or an evidence pack. The record holds hashes and identifiers, not prompts, responses or customer data, so a pack can go to an auditor without exposing that content.
4. Who holds the keys
The customer. Firmantia is built so that it never holds a customer's private key. The service key that signs each batch is a P-256 key; today it is a file on the machine that seals the record, created there and never sent anywhere. Hardware and cloud key storage are not built yet. People who approve an agent's action sign with their own keys.
5. What credentials the tool holds
Read access to the agent platform's audit export (today, a file the customer exports), write access to its own database, and its own signing key. It holds no credentials to the agent platform's systems and none to any Firmantia service.
6. How the record is protected from alteration
Every record is hashed. Batches list their records' hashes, link to the batch before, are signed, and are time stamped by an authority outside the operator's control. The database refuses updates and deletes. If one byte of a record changes, verification fails and names the record.
7. Which cryptography
SHA-256; ECDSA P-256 with SHA-256; RFC 3161 time stamps. Built in cryptography only: Web Crypto in the browser verifier, Node's crypto module in the tools. No third party cryptography library.
8. Whether prompts or data are sent to any AI service
No. Firmantia does not call any AI model or AI service.
9. Does it call out to the internet
Only to the time stamp authority (and to any public log the customer turns on), and only with a hash. Verification makes no network calls at all.
10. What happens if Firmantia disappears
The evidence packs still verify, forever. The verifier is one HTML file that runs offline; the pack carries the records, the chain, the signatures, the key registry and the time stamp tokens. Nothing in the check depends on us.
11. What happens if it is removed
The record and the packs already exported stay with the customer and keep verifying. Nothing has to be uninstalled from the agent platform.
12. Does it sit in the agent's path
No. It reads the platform's audit export after the fact. It cannot slow down, block or change what an agent does.
13. How updates are delivered and verified
Not decided yet. There is no published release today.
14. What logging the tool itself does
The command line tool prints what it did (records stored, batches sealed, time stamps received) to the terminal. It sends no telemetry.
15. Software bill of materials
The record's core depends on one library, zod, for record schemas, and on the Node.js runtime. The database adapter adds pg, the standard PostgreSQL driver. The verifier is built into one HTML file that loads nothing from outside. A formal software bill of materials will be published with the first release.
16. Vulnerability disclosure
Tell us through the early access form and say it is a security report; a person reads it. A security contact address and a disclosure policy will be published before launch.
17. Which certifications it holds
None. Firmantia is in development; it holds no certification and has had no outside security review.
18. Data retention on our side
None. Firmantia runs in the customer's environment and keeps nothing on ours. The early access form on this site is the only place we receive information, and it is not stored yet.
19. Licence and support
Not set yet. Both will be agreed with early access partners.
20. Roadmap items a buyer may be waiting on
A hosted service; hardware and cloud key storage; an in-country time stamp authority; connectors beyond Microsoft Agent 365; Arabic reports.
Coming later: the same verifiable record for the AI coding agents building your software.
Sensitive and regulated information
The record is built not to hold it. It keeps hashes of inputs and outputs, never the content, and the agent fields never name a person. The platform's own audit export, which the customer reads in, stays where the customer keeps it.