SECURITY REVIEW

Direct answers for security and procurement teams.

Production architecture, data controls and diligence materials for security and procurement teams.

Effective and last reviewed: 16 July 2026

Production security facts

Production use

Production deployments use approved sources, scoped connectors, customer-set authority and execution proof.

Hosting and isolation

The managed service runs on European infrastructure. Every deployment has documented hosting, isolation, data-flow and transfer boundaries.

Customer-controlled data

Customer systems remain authoritative. SupraOS works from approved sources, objects and fields and can begin entirely read-only.

Connector authority

Credentials are scoped at the provider and narrowed further by the approved program, policy, role and exact-action approval.

Verified system changes

Each connected-system change is read back after execution and compared with the intended state before that connector action is verified.

Agent and model control

Models reason inside customer evidence and permissions. Named authority controls consequential actions, and material changes return for renewed approval.

Customer data and model training

Customer data and model-provider rules are defined in AI governance. Every model provider is disclosed before use.

Receipts

Each Receipt connects evidence, authority, approval, action, resulting system state and verification outcome in one execution record.

DPA and security documentation

Security teams receive the DPA, security schedule, architecture, data flows, subprocessors, control details and questionnaire responses under NDA.

Security incidents and reporting

The Head of Security monitors security@supraos.co. Vulnerability reporting and coordinated-disclosure instructions are published in the Security Contact.

Request the security review packet

Review architecture, data flows, customer isolation, DPA terms, subprocessors, execution controls and deployment commitments with the SupraOS security team.