Security & architecture

Security is the substrate the platform is built on.

This page is written for your IT and security team. Every layer of an InsightLab deployment - identity, sessions, service channels, data paths, and the agents themselves - ships with security controls on by default.

Identity & access

Passkey-first, phishing-resistant sign-in.

WebAuthn passkeys

Primary authentication is passwordless and phishing-resistant. No shared secrets to leak, reuse, or phish.

Policy-based step-up

Sensitive actions trigger step-up MFA - authenticator-app TOTP or SMS OTP - driven by per-action policy, not blanket friction.

Hardened sessions

Device-aware sessions with token rotation and replay-resistant access tokens. Sessions are revocable per device.

Service & API defense

No implicit trust between services.

mTLS service channels

Service-to-service traffic authenticates both ends. A compromised network segment doesn't grant API access.

OAuth2 + OIDC controls

Standards-based authorization on every API surface, with scoped tokens and short-lived credentials.

WAF & rate limits

Per-endpoint rate limiting and WAF filtering in front of public surfaces; signed channels and connection-level throttling for streams and WebSockets.

Governed autonomy

Agents act only through the policy engine.

Policy gates on every action

No agent talks to an actuator directly. SLA windows, safety rules, and jurisdiction constraints are enforced at the orchestration layer before any action releases.

Human approval gates

High-stakes decisions route to operators for explicit approval. Every override path is a first-class feature, not an afterthought.

Attributable decisions

Every agent action carries a decision trace: the inputs it saw, the policies it passed, and who (or what) approved it.

Data & observability

Encrypted paths, audit-ready trails.

Encryption everywhere

Data encrypted in transit and at rest, with managed secrets and key-rotation workflows.

SIEM-ready logging

Structured audit trails and logs ready to stream into your SIEM, with anomaly-detection pipelines tuned for rapid incident response.

24×7 monitoring

Agent behavior, service health, and decision quality are monitored continuously with incident-aware orchestration.

Compliance

Ask us the hard questions.

Our detailed security documentation, architecture diagrams, and compliance roadmap are available under NDA. Email info@insightlab.cloud and we'll set up a session with your security team - we respond within one business day.