Security

Authentication, API keys, network security, and hardening guidance.

Security

Overview

AgentTrust implements defense-in-depth security: authentication, encryption at rest, audit integrity, PII detection, and tier-based authorization. This page summarizes security controls for operators and developers.

Why It Matters

AI governance systems handle sensitive agent inputs/outputs. Security misconfiguration can expose audit data or bypass policy enforcement.

Prerequisites

  • Full edge gateway for production security features
  • Enterprise tier for SSO and SOC2 export; Team tier for hash-chain verification

Step-by-Step Guide

Authentication

LayerMechanism
SDK → Edge gatewayX-AgentTrust-Token header only — the Authorization header is never read
DashboardJWT session
Enterprise SSOSAML via /v1/sso/*
Embedded gatewayAuthorization: Bearer only — an auto-generated unsigned JWT carrying a team tier claim

Critical: Set AUTH_ENABLED=true in all non-dev environments.

Authorization

  • JWT contains tier claim — gateway enforces capability matrix
  • Rate limiting: 70 req/min (60 + 10 burst) on /v1/runtime/validate, bucketed by the X-Agent-ID header; 20/min per IP on /v1/auth/* (see gateway/config/rate_limits.yaml)
  • Team management via /v1/team/*

Encryption

DataProtection
Audit payloads at restAES-256-GCM (AGENTRUST_AUDIT_ENCRYPTION_KEY)
Archive store (S3/GCS)AES-256 at rest
Audit packagesEd25519 signing (AGENTRUST_SIGNING_KEY)
In transitTLS (operator responsibility)

Audit integrity

  • Append-only ledger with content hashes
  • Hash chain verification: GET /v1/audit/chain/verify (Team tier and above)
  • Ledger hashes are permanent (required for integrity; not erasable)

PII handling

  • Policy engine detects SSN, email, API keys, passwords
  • PII fields masked in hot store within 24 hours
  • Erasure endpoint: DELETE /v1/audit/executions/{id}/pii
  • LLM judge receives truncated input/output only (never full payload)

Secret management

SecretRotation
AGENTRUST_JWT_SECRETQuarterly minimum
AGENTRUST_KEY / API keysOn team member departure
DATABASE_URL credentialsPer org policy
AGENTRUST_AUDIT_ENCRYPTION_KEYAnnual; requires re-encryption plan

Kill-switch

export AGENTRUST_ENABLED=false

Instant rollback — all governance paths become no-ops.

Examples

Verify auth:

curl -H "X-AgentTrust-Token: $AGENTRUST_KEY" http://localhost:8000/v1/auth/check

Best Practices

  • Never commit API keys or JWT secrets to version control
  • Use secret managers (Vault, AWS Secrets Manager, K8s Secrets)
  • Enable audit encryption in production
  • Run AUTH_ENABLED=true always in production
  • Complete AIIA for high-risk domains
  • Follow Incident Response procedures

Common Mistakes

  • AUTH_ENABLED=false in production
  • Exposing gateway port 8000 without TLS/reverse proxy
  • Storing production keys in .env files in git repos
  • Using embedded gateway for regulated production data

Troubleshooting

IssueFix
401 on all requestsVerify token; check JWT secret matches
PII alerts floodingEnable pii_controls policy pack; redact inputs
Chain verify failsDo not manually edit audit database