Direct answers for security and procurement teams.
Production architecture, data controls and diligence materials for security and procurement teams.
Effective and last reviewed: 16 July 2026
Production security facts
Production use
Production deployments use approved sources, scoped connectors, customer-set authority and execution proof.
Hosting and isolation
The managed service runs on European infrastructure. Every deployment has documented hosting, isolation, data-flow and transfer boundaries.
Customer-controlled data
Customer systems remain authoritative. SupraOS works from approved sources, objects and fields and can begin entirely read-only.
Connector authority
Credentials are scoped at the provider and narrowed further by the approved program, policy, role and exact-action approval.
Verified system changes
Each connected-system change is read back after execution and compared with the intended state before that connector action is verified.
Agent and model control
Models reason inside customer evidence and permissions. Named authority controls consequential actions, and material changes return for renewed approval.
Customer data and model training
Customer data and model-provider rules are defined in AI governance. Every model provider is disclosed before use.
Receipts
Each Receipt connects evidence, authority, approval, action, resulting system state and verification outcome in one execution record.
DPA and security documentation
Security teams receive the DPA, security schedule, architecture, data flows, subprocessors, control details and questionnaire responses under NDA.
Security incidents and reporting
The Head of Security monitors security@supraos.co. Vulnerability reporting and coordinated-disclosure instructions are published in the Security Contact.
Request the security review packet
Review architecture, data flows, customer isolation, DPA terms, subprocessors, execution controls and deployment commitments with the SupraOS security team.