Skip to content
Tide Technology Solutions
Menu

Security & compliance

Security built into every agent.

Agentic AI doesn’t just answer questions. It takes actions in your systems. So we secure the whole stack: the harness that controls what agents can do, the models behind them and the data they touch. These practices are built into every workflow and product we ship.

Layer 1

The agent harness

The harness is the software around the model that decides what an agent can see, which tools it can use and when a person has to step in. It’s where most agentic risk is controlled.

Least-privilege access

Each agent gets only the tools, systems and data its workflow needs, with narrowly scoped credentials. Nothing more.

Approval gates

High-impact actions such as sending messages, changing records, moving money or deleting data wait for explicit human approval.

Prompt-injection defenses

Content from emails, files and the web is treated as data, never as instructions. Untrusted input is isolated from the agent’s instructions and permissions.

Sandboxed execution

Agents run in isolated environments with allowlisted network access, so a misbehaving step can’t reach systems it shouldn’t.

Validated outputs

Agent outputs are checked against schemas and business rules before anything is written to your systems.

Limits & kill switch

Rate, spend and action limits on every workflow, plus the ability to pause any agent instantly.

Layer 2

The models

We choose models per task, balancing capability, cost and how sensitive the data is, and we test them before they touch your work.

Open-weight models, privately hosted

For the most sensitive workloads, we run open-weight models in isolated, private infrastructure, so data never leaves environments under our control.

Frontier models, on your terms

Where frontier models add real value, we use them through enterprise agreements with zero data retention where available. You decide which workloads can use them.

Never trained on your data

Your data is used only to do your work. It is never used to train models and never shared with other clients.

Evaluated & red-teamed

Every workflow is tested against real examples and adversarial cases before launch, and re-tested whenever a model or prompt changes.

Layer 3

Your data

Standard security controls, applied consistently across every product and custom workflow.

Encryption & access control

Data is encrypted in transit and at rest. Access is role-based and limited to the people who need it.

Secrets kept from the model

Passwords and API keys live in a secure vault and are applied at the tool layer. Models never see them.

Client isolation

Each client’s data, credentials and agents are kept separate from every other client’s.

Full audit trail

Every model call, tool action and approval is logged: what happened, when, who approved it and what it was based on.

Regulated data & case files

Built for HIPAA.

Case files are full of medical records, legal documents and personal histories. Casework and any custom workflow that handles protected health information are designed to meet HIPAA requirements for handling PHI, and we work with clients on Business Associate Agreements.

PHI is only processed in approved environments, access follows the minimum-necessary standard, and every view and action on a case file is recorded in the audit trail.

Human in the loop

AI does the work. People make the calls.

Our agents never take a consequential action on their own. They prepare, draft and recommend, and a person on your team approves. In Casework, a qualified professional reviews every output, checks the citations and signs off. Accountability stays where it belongs.

Have security questions?

We’re happy to walk your team through our architecture, data handling and compliance posture.