Trust & safetyGuardrails your
Guardrails your
auditor will like.
Write the rules once. Rheostat enforces them on every flag, every prompt and every agent action — and keeps the receipts.
Production policies
4 active- Block PII in agent outputsredact · email, card, national ID
- Daily spend cap$500 per agent · hard stop
- Human approval above $250refunds, credits, payouts
- External email from agentsblocked until reviewed
- Prompt changes need review2 approvers · production only
SOC 2TYPE II
ISO27001
GDPREU · UK
HIPAABAA ready
CCPAcompliant
policy:name: refunds-need-a-humanapplies_to: agents/billing-*when:action: refundamount_usd: "> 250"then:require: approvalapprovers: [finance-oncall]timeout: 30m → denyaudit: forever
Policies live
in your repo.
- Reviewed like codePull requests, diffs and approvals — the same workflow as the rest of your stack.
- Tested before mergeReplay last week of traffic against a new policy and see what it would have blocked.
- Enforced at the edgeEvaluated in under 20 ms, before an agent’s action leaves your network.
Every change,
signed and kept.
Humans and agents write to the same log. Export it to your SIEM or hand it straight to an auditor.
| Time | Actor | Action | Result |
|---|---|---|---|
| 14:02:09 | Agentbilling-agent | refund $420 → approval requested | Held |
| 14:03:51 | Humanmaya.okafor | approved refund A-2291 | Approved |
| 14:10:22 | Agentoutreach-agent | email 1,200 customers | Blocked |
| 14:31:07 | Humandev.ramos | rollout new-checkout 5% → 25% | Applied |
| 14:32:40 | Systemrheostat | auto-rollback new-checkout → 0% | Applied |
Your data stays
where you put it.
EUFrankfurteu-central · 9 ms
UKLondonuk-south · 7 ms
USVirginiaus-east · 11 ms
APACSingaporeap-southeast · 14 ms
Audits got boring.
“Our SOC 2 auditor asked for evidence of change control. We sent one link to the audit log and the question was closed.”
“Policy as code means the PII rule is reviewed like any other pull request. No more spreadsheet of exceptions.”
“EU data stays in Frankfurt, US data in Virginia. That one setting unblocked our biggest customer.”
Security questions.
- Which certifications do you hold?
- SOC 2 Type II, ISO 27001 and ISO 27701. Reports are available under NDA from the trust centre.
- Where is my data stored?
- In the region you choose: EU (Frankfurt), US (Virginia), UK (London) or APAC (Singapore).
- Can policies block a release?
- Yes. A failing policy stops the rollout before the first percentage and tells the author why.
- Do you support SSO and SCIM?
- SAML and OIDC single sign-on on every paid plan, SCIM provisioning on Enterprise.
Ship fast,
stay compliant.
Get the security pack: our SOC 2 report, pen test summary and data processing agreement.