WebAuthn passkeys
Primary authentication is passwordless and phishing-resistant. No shared secrets to leak, reuse, or phish.
Security & architecture
This page is written for your IT and security team. Every layer of an InsightLab deployment - identity, sessions, service channels, data paths, and the agents themselves - ships with security controls on by default.
Identity & access
Primary authentication is passwordless and phishing-resistant. No shared secrets to leak, reuse, or phish.
Sensitive actions trigger step-up MFA - authenticator-app TOTP or SMS OTP - driven by per-action policy, not blanket friction.
Device-aware sessions with token rotation and replay-resistant access tokens. Sessions are revocable per device.
Service & API defense
Service-to-service traffic authenticates both ends. A compromised network segment doesn't grant API access.
Standards-based authorization on every API surface, with scoped tokens and short-lived credentials.
Per-endpoint rate limiting and WAF filtering in front of public surfaces; signed channels and connection-level throttling for streams and WebSockets.
Governed autonomy
No agent talks to an actuator directly. SLA windows, safety rules, and jurisdiction constraints are enforced at the orchestration layer before any action releases.
High-stakes decisions route to operators for explicit approval. Every override path is a first-class feature, not an afterthought.
Every agent action carries a decision trace: the inputs it saw, the policies it passed, and who (or what) approved it.
Data & observability
Data encrypted in transit and at rest, with managed secrets and key-rotation workflows.
Structured audit trails and logs ready to stream into your SIEM, with anomaly-detection pipelines tuned for rapid incident response.
Agent behavior, service health, and decision quality are monitored continuously with incident-aware orchestration.
Compliance
Our detailed security documentation, architecture diagrams, and compliance roadmap are available under NDA. Email info@insightlab.cloud and we'll set up a session with your security team - we respond within one business day.