guardroute.ai

Security and control

How GuardRoute keeps high-risk actions under policy before execution, and an honest compliance status.

GuardRoute is designed as a control layer in front of sensitive actions. It does not hold funds, custody assets, or execute transactions on your behalf.

Policy before execution

Routing rules and risk thresholds are evaluated before your systems receive a release signal. High-risk paths are designed to fail closed when policy requires a stop or hold.

Separation of request and approval

The party or system that requests an action is distinct from approvers and reviewers named on the route card.

Recorded overrides

When policy permits an override, reviewer identity, reason, and timestamp are retained as part of the decision record.

Fail-closed design intent

For configured high-risk actions, ambiguous or missing signals are designed to route to hold or block rather than silent allow — scoped to your deployment policy.

Production data handling — retention, residency, and subprocessors — is scoped in the customer agreement.

Funds and execution

Confirmed

GuardRoute does not hold funds or execute transactions. It returns route decisions and control requirements; your systems execute.

SOC 2

In readiness

Readiness work is underway. No SOC 2 report has been issued.

ISO 27001

Not certified

No ISO 27001 certification is claimed.

Penetration test

By request

No penetration-test summary is published. Security questionnaires and architecture reviews are handled with qualified teams under NDA.

Responsible disclosure

Report security concerns to security@stratedgeworkflow.com. Security questionnaires and architecture reviews are handled with qualified teams under NDA.

Privacy · Public demo